Developer · Remote MCP server

Cisa Cybersecurity MCP Server

CISA KEV with BOD 26-04 deadlines, SSVC prioritization, and the ICS advisory corpus (CSAF). Keyless.

What the MCP Registry states

The entry as published to the official MCP Registry (read 2026-10-04), latest version.

Registry name
io.github.cyanheads/cisa-cybersecurity-mcp-server
Version
0.3.0
Status
Active
Category
developer
Transport
Streamable HTTP, stdio (local process)
Package
npm
Published
2026-09-25
Updated
2026-09-25
Publisher
cyanheads (GitHub) · 140 servers with pages here
Listed under
Calendar MCP servers
Repository
github.com/cyanheads/cisa-cybersecurity-mcp-server
Source
Registry API entry

Remote endpoints

TransportURLHeaders declared
Streamable HTTPhttps://cisa-cybersecurity.caseyjhand.com/mcpNone

Packages

RegistryPackageVersionTransportEnvironment variables
npmruntime: node@cyanheads/cisa-cybersecurity-mcp-server0.3.0stdioMCP_LOG_LEVEL, CISA_KEV_REFRESH_CRON, CISA_CSAF_MIRROR_PATH, CISA_CSAF_MIRROR_AUTO_INIT, CISA_CSAF_REFRESH_CRON, CISA_VULNRICHMENT_CACHE_TTL_SECONDS, CISA_FEED_CACHE_TTL_SECONDS, CISA_HTTP_TIMEOUT_MS
npmruntime: node@cyanheads/cisa-cybersecurity-mcp-server0.3.0HTTPMCP_HTTP_HOST, MCP_HTTP_PORT, MCP_HTTP_ENDPOINT_PATH, MCP_AUTH_MODE, MCP_LOG_LEVEL, CISA_KEV_REFRESH_CRON, CISA_CSAF_MIRROR_PATH, CISA_CSAF_MIRROR_AUTO_INIT, CISA_CSAF_REFRESH_CRON, CISA_VULNRICHMENT_CACHE_TTL_SECONDS, CISA_FEED_CACHE_TTL_SECONDS, CISA_HTTP_TIMEOUT_MS

How to connect Cisa Cybersecurity MCP Server

Cisa Cybersecurity MCP Server is a remote MCP server: there is nothing to install. Its endpoint is https://cisa-cybersecurity.caseyjhand.com/mcp, served over Streamable HTTP. In an assistant that accepts remote MCP servers (often under a setting named connectors, integrations or tools), add a new server and give it this URL; in a client configured by file, add it as a remote (HTTP) server with the same URL.

No headers are declared in the registry entry. If the server needs you to sign in, a client that supports MCP authorization opens the service's own sign-in page when it first connects.

It can also run locally from a Node.js package published to the npm registry: @cyanheads/cisa-cybersecurity-mcp-server version 0.3.0. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Node.js; clients usually start it with npx — the usual command is npx -y @cyanheads/cisa-cybersecurity-mcp-server@0.3.0; the entry names node as the runtime. It reads these environment variables: MCP_LOG_LEVEL, CISA_KEV_REFRESH_CRON, CISA_CSAF_MIRROR_PATH, CISA_CSAF_MIRROR_AUTO_INIT, CISA_CSAF_REFRESH_CRON, CISA_VULNRICHMENT_CACHE_TTL_SECONDS, CISA_FEED_CACHE_TTL_SECONDS and CISA_HTTP_TIMEOUT_MS; set them in the client's configuration for this server.

It can also run locally from a Node.js package published to the npm registry: @cyanheads/cisa-cybersecurity-mcp-server version 0.3.0. The package starts a local server that speaks MCP over Streamable HTTP; the client then connects to it by URL (the entry names node as the runtime). It reads these environment variables: MCP_HTTP_HOST, MCP_HTTP_PORT, MCP_HTTP_ENDPOINT_PATH, MCP_AUTH_MODE, MCP_LOG_LEVEL, CISA_KEV_REFRESH_CRON, CISA_CSAF_MIRROR_PATH, CISA_CSAF_MIRROR_AUTO_INIT, CISA_CSAF_REFRESH_CRON, CISA_VULNRICHMENT_CACHE_TTL_SECONDS, CISA_FEED_CACHE_TTL_SECONDS and CISA_HTTP_TIMEOUT_MS; set them in the client's configuration for this server.

In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):

{
  "mcpServers": {
    "cisa-cybersecurity-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@cyanheads/cisa-cybersecurity-mcp-server@0.3.0"
      ],
      "env": {
        "MCP_LOG_LEVEL": "<value>",
        "CISA_KEV_REFRESH_CRON": "<value>",
        "CISA_CSAF_MIRROR_PATH": "<value>",
        "CISA_CSAF_MIRROR_AUTO_INIT": "<value>",
        "CISA_CSAF_REFRESH_CRON": "<value>",
        "CISA_VULNRICHMENT_CACHE_TTL_SECONDS": "<value>",
        "CISA_FEED_CACHE_TTL_SECONDS": "<value>",
        "CISA_HTTP_TIMEOUT_MS": "<value>"
      }
    }
  }
}

Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect

More from cyanheads (GitHub)

All 140 →
ServerRunsEndpoint or package
Calculator MCP ServerEvaluate, simplify, and differentiate mathematical expressions.Remote & Local · HTTP, stdiocalculator.caseyjhand.com
Cdc Health MCP ServerSearch and query CDC public health data — mortality, vaccinations, surveillance, behavioral risk.Remote & Local · HTTP, stdiocdc.caseyjhand.com
Census MCP ServerQuery U.S. Census Bureau data, variables, and geography via MCP.Remote & Local · HTTP, stdiocensus.caseyjhand.com
Cern Opendata MCP ServerSearch CERN Open Data, fetch records, files, analysis environments, CMS good-run lists, HLT paths.Remote & Local · HTTP, stdiocern-opendata.caseyjhand.com
cern-inspire-mcp-serverSearch INSPIRE-HEP papers, authors, experiments, HEPData records; get citation metrics and BibTeX.Remote & Local · HTTP, stdiocern-inspire.caseyjhand.com
Chembl MCP ServerLink compounds to protein targets, rank bioactivity, and look up drug mechanisms and indications.Remote & Local · HTTP, stdiochembl.caseyjhand.com
Clinicaltrialsgov MCP ServerSearch ClinicalTrials.gov — find studies, retrieve results, match patients to eligible trials.Remote & Local · HTTP, stdioclinicaltrials.caseyjhand.com
Clipboard MCP ServerRead, write, and inspect the system clipboard on macOS, Linux (X11/Wayland), and Windows via MCP.Local · stdio, HTTPnpm: @cyanheads/clipboard-mcp-server
Coingecko MCP ServerCrypto market data via CoinGecko — prices, markets, history, trending, and deep coin metadata.Local · stdio, HTTPnpm: @cyanheads/coingecko-mcp-server
College Scorecard MCP ServerSearch, compare, and analyze U.S. college data — costs, earnings, programs, and outcomes.Local · stdio, HTTPnpm: @cyanheads/college-scorecard-mcp-server
Congressgov MCP ServerAccess U.S. congressional data - bills, votes, members, committees - via MCP.Remote & Local · HTTP, stdiocongressgov.caseyjhand.com
Courtlistener MCP ServerSearch US court opinions, federal dockets, judges, citations, and oral arguments via CourtListener.Remote & Local · HTTP, stdiocourtlistener.caseyjhand.com

More developer servers

All 6,250 →
ServerRunsEndpoint or package
CIPPMCP server for CIPP — M365 multi-tenant management for MSPs (users, tenants, policies).Local · stdioOCI image (Docker): ghcr.io/wyre-technology/cipp-mcp:v1.7.3
CIPP MCPFirst single-binary CLI for CIPP - offline SQLite store, fleet posture analytics, and.Local · stdioMCP Bundle (.mcpb): Servosity/msp-skills/releases/download/cipp-v0.1
CirdanAI infrastructure cartographer & MCP server: fingerprints, graphs & watches live infra for agents.Local · stdionpm: @cirdanops/cli
CISA Cybersecurity & ICS Advisories — buy per-query in-session (cisaalerts)CISA advisories & ICS alerts: new CVEs, remediation. Register in-session — free testnet funds.Remote · HTTPa2awire.com
Cisco MerakiMCP server for the Cisco Meraki Dashboard: networks, devices, wireless, switch, appliance.Local · stdioOCI image (Docker): ghcr.io/wyre-ai/meraki-mcp:v1.1.10
Cisco MerakiMCP server for the Cisco Meraki Dashboard: networks, devices, wireless, switch, appliance.Local · stdioOCI image (Docker): ghcr.io/wyre-technology/meraki-mcp:v1.1.3
Cisco SD-WAN MCP ServerMCP server for Cisco Catalyst SD-WAN (vManage): fabric inventory, device health, alarms, policies.Local · stdioPyPI: cisco-sdwan-mcp
Cisco UmbrellaMCP server for Cisco Umbrella's deployment, admin, policy, reporting, and investigate APIs.Local · stdioOCI image (Docker): ghcr.io/wyre-ai/cisco-umbrella-mcp:v1.0.0