{"note":"Free sample; paid endpoint accepts caller-supplied CVE lists.","methodologyUrl":"https://zeroworker-security-api.zeroworker-lab.workers.dev/methodology","dataStatus":{"cisaKev":{"source":"cisa-kev","fetchedAt":"2026-10-10T19:06:06.640Z","ageSeconds":20053,"stale":false,"cache":"kv","sourceDate":"2026-10-08T20:09:18.9833Z"},"firstEpss":{"source":"first-epss","fetchedAt":"2026-10-10T06:06:06.848Z","ageSeconds":66853,"stale":false,"cache":"kv","sourceDate":"2026-10-09"}},"sources":{"kevCatalogVersion":"2026.10.08","kevDateReleased":"2026-10-08T20:09:18.9833Z","epss":"FIRST EPSS"},"results":[{"cve":"CVE-2021-44228","dataAvailable":true,"score":100,"tier":"urgent","epss":0.99999,"epssPercentile":1,"inKev":true,"ransomwareKnown":true,"vendor":"Apache","product":"Log4j2","kevDateAdded":"2021-12-10","kevDueDate":"2021-12-24","requiredAction":"For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.","reasons":["Listed in CISA KEV (known exploitation observed)","CISA marks known ransomware campaign use","EPSS 100.00%","EPSS percentile 100.00%"]},{"cve":"CVE-2023-44487","dataAvailable":true,"score":95,"tier":"urgent","epss":0.99999,"epssPercentile":0.99998,"inKev":true,"ransomwareKnown":false,"vendor":"IETF","product":"HTTP/2","kevDateAdded":"2023-10-10","kevDueDate":"2023-10-31","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","reasons":["Listed in CISA KEV (known exploitation observed)","EPSS 100.00%","EPSS percentile 100.00%"]}]}