---
sourceDocument: Zurich Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/security-management

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# CISA Known Exploit Vulnerability (KEV) Integration

# CISA Known Exploit Vulnerability (KEV) Integration {#ariaid-title1}

Release version: Zurich  
Updated March 12, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of CISA Known Exploit Vulnerability (KEV) Integration

The CISA Known Exploit Vulnerability (KEV) Integration enhances ServiceNow Vulnerability Response by ingesting prioritized vulnerability data from the U.S.
Cybersecurity \& Infrastructure Security Agency (CISA).
This integration helps organizations efficiently prioritize and remediate actively exploited vulnerabilities by mapping CISA's Known Exploited Vulnerabilities catalog to your existing Common Vulnerabilities and Exposures (CVE) data within ServiceNow.
Show full answer Show less  
CISA provides critical information on the most exploited vulnerabilities to assist government agencies and corporations in urgent remediation efforts. The integration automatically updates vulnerability records daily, ensuring your instance stays synchronized with the latest threat intelligence.

## Key Features

* **Data Enrichment:** Automatically enriches CVE vulnerability records with CISA KEV data, including CVE ID, due dates, date added, vendor/project, product, and ransomware campaign indicators.
* **Ransomware Indicators:** Starting with Vulnerability Response version 21.0, the integration flags vulnerabilities known to be used in ransomware campaigns for enhanced risk prioritization.
* **Roll-Up to Third-Party Entries:** CISA data is rolled up to the Third-Party Vulnerability Entries table, consolidating due dates and SSVC (Stakeholder-Specific Vulnerability Categorization) values to assist remediation workflows.
* **Automated Scheduled Jobs:** The integration runs automatically daily via scheduled jobs but can also be executed manually to ensure timely synchronization of vulnerability data.
* **Secure Configuration:** Uses a designated run-as user (default: VR.System) for secure data ingestion. This user account should not be altered.
* **Native System Integration:** The integration is included by default and is accessible from the Vulnerability Response module under Administration \> Integrations.

## Practical Benefits for ServiceNow Customers

* Gain timely, prioritized insights on actively exploited vulnerabilities directly within your Vulnerability Response instance.
* Accelerate remediation by focusing on vulnerabilities that pose immediate risk based on CISA's authoritative intelligence.
* Utilize ransomware campaign flags to strengthen risk assessment and incident response prioritization.
* Maintain up-to-date vulnerability data automatically, reducing manual update efforts and improving security posture.
* Leverage SSVC categorization for more nuanced stakeholder-specific vulnerability management.  
The Vulnerability Response integration with the CISA Known Exploited Vulnerabilities
(KEVs) catalog ingests data to help you effectively prioritize and remediate these
vulnerabilities.

## Request apps on the Store {#cisa-vuln-integration__section_wlq_1kz_thb}

Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).{#cisa-vuln-integration__inline-send-to-store}
CISA enables urgent and prioritized remediation of actively exploited vulnerabilities for
government agencies and corporations.

## About CISA {#cisa-vuln-integration__section_cwm_w4s_c5b}

Cybersecurity \& Infrastructure Security Agency (CISA) is a U.S. Cybersecurity \& Infrastructure Security Agency that publishes a report on the most exploited vulnerabilities. It easily integrates with Vulnerability Response to map Common Vulnerabilities and Exposures (CVE) vulnerabilities enriching the data in your instance. This information is then rolled up to the Third-Party Vulnerability Entries table. The earliest due date is considered for the roll-up to the vulnerable items.  
Note:  
The CISA Exists check box for CVEs retrieved by CISA.  
Values retrieved from the CISA integration:

* CVE ID
* Due date
* Date added
* Vendor/Project
* Product
* Known ransomware (starting from v21.0 of Vulnerability Response, a new field Known To Be Used in Ransomware Campaigns is ingested from the CISA Known Exploited Vulnerabilities (KEVs) catalog. It's indicated by the flagging of the Known ransomware field on the National Vulnerability Entry database table. The flag is set at the Common Vulnerabilities and Exposures (CVE) level and rolled up to the third-party entry (TPE).
{#cisa-vuln-integration__ul_g2y_fwk_c5b}

There is a configured run-as user for each integration record. The default value for this
user is VR.System. Do not change this value.  
Note:  
The CISA Exploit section of the third-party entry form also displays SSVC (Stakeholder-Specific Vulnerability Categorization) values rolled up from CVE entries. See [SSVC enrichment for CVEs](https://www.servicenow.com/docs/oakfu0FK5KEoaagrRGs2ag "Unified Security Exposure Management (USEM) enriches CVE entries with SSVC (Stakeholder-Specific Vulnerability Categorization) decision values from the National Vulnerability Database (NVD). These values provide additional risk signals that you can use to analyze and prioritize vulnerabilities. This enrichment is available only in USEM.") for more information.

## Scheduled jobs {#cisa-vuln-integration__section_g2x_3ns_c5b}

The CISA Integration is invoked automatically as a daily scheduled job. You can also
execute individual scheduled jobs manually. Scheduled jobs simplify the vulnerability
remediation life cycle by keeping the instance synchronized with other vulnerability
management systems.

## Available versions {#cisa-vuln-integration__section_gkd_vpw_zhb}

{#cisa-vuln-integration__table_tqh_wpw_zht__entry__2}

| Release version | Release Notes |
|-|-|
| Vulnerability Response v16.5, v18.0 Vulnerability Response Integration with CISA v1.0, v1.2 |   |
[ ]

{#cisa-vuln-integration__table_tqh_wpw_zht}

## Viewing the CISA integration {#cisa-vuln-integration__section_ift_yxh_x1b}

To view the CISA integration, navigate to Vulnerability ResponseAdministrationIntegrationsCISA Known Exploit Vulnerability Integration.  
The following integrations are included in the base system.  
Note:  
Only the CISA Integration is active, by default.  
{#cisa-vuln-integration__table_sbn_qlp_dt__entry__2}

| Integration | Description |
|-|-|
| Cybersecurity \& Infrastructure Security Agency (CISA) Integration | Retrieves CISA vulnerability data (CVE) and enriches the existing vulnerability data. This integration is set automatically to run daily. |
[Table 1. CISA integration]

{#cisa-vuln-integration__table_sbn_qlp_dt}

To view data in third-party vulnerabilities, see [View Vulnerability Response vulnerability libraries](https://www.servicenow.com/docs/_eKoqYMpvJQyGWglBPJNmQ "You can view vulnerability data imported from the National Vulnerability Database (NVD), Common Weakness Enumeration (CWE), or third-parties to decide whether to escalate a remediation task.").

*[\>]: and then


