{
  "$schema": "https://verifymcp.io/schemas/changelog.json",
  "server": "com-a2awire-data-cisa-known-exploited-vulnerability-catalog",
  "component": "mcp-data-cisa-known-exploited-vulnerabilities-kevwatch-aedaf3-http",
  "generated_at": "2026-09-25T18:05:13.494Z",
  "tracking_since": "2026-09-02",
  "counts": {
    "critical": 1,
    "security": 18,
    "functional": 0,
    "cosmetic": 0
  },
  "events": [
    {
      "id": "chg_01a0d20a-f4bb-7ac0-a6a5-2cff1b2c0e2c",
      "kind": "check.reverified",
      "family": "auth-oauth",
      "subject_kind": "check",
      "subject": "auth-oauth",
      "subject_child": "",
      "from_code": "auth.unreachable",
      "to_code": "auth.none_destructive",
      "from_value": "unverified",
      "to_value": "fail",
      "materiality": "critical",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "tool": "hire_and_execute"
      },
      "occurred_on": "2026-09-24",
      "occurred_at": "2026-09-24 06:12:08.281379+00",
      "observed_since": "2026-09-23",
      "source": "scan",
      "summary": "Authorization (unverified → fail)",
      "link": "https://verifymcp.io/servers/com-a2awire-data-cisa-known-exploited-vulnerability-catalog/mcp-data-cisa-known-exploited-vulnerabilities-kevwatch-aedaf3-http#chg-chg_01a0d20a-f4bb-7ac0-a6a5-2cff1b2c0e2c"
    },
    {
      "id": "chg_01a0d20a-f4bd-7488-93cf-4d08a1f5581f",
      "kind": "check.verdict",
      "family": "transport",
      "subject_kind": "check",
      "subject": "transport",
      "subject_child": "",
      "from_code": "transport.unreachable",
      "to_code": "transport.verified",
      "from_value": "fail",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "transport": "streamable-http"
      },
      "occurred_on": "2026-09-24",
      "occurred_at": "2026-09-24 06:12:08.281379+00",
      "observed_since": "2026-09-23",
      "source": "scan",
      "summary": "Transport (fail → pass)",
      "link": "https://verifymcp.io/servers/com-a2awire-data-cisa-known-exploited-vulnerability-catalog/mcp-data-cisa-known-exploited-vulnerabilities-kevwatch-aedaf3-http#chg-chg_01a0d20a-f4bd-7488-93cf-4d08a1f5581f"
    },
    {
      "id": "chg_01a0d20a-f4be-71be-8cae-e3ec2a9a23f2",
      "kind": "check.reverified",
      "family": "tool-safety-injection",
      "subject_kind": "check",
      "subject": "tool-safety-injection",
      "subject_child": "",
      "from_code": "toolsafety.unreachable",
      "to_code": "toolsafety.injection_clean",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-24",
      "occurred_at": "2026-09-24 06:12:08.281379+00",
      "observed_since": "2026-09-23",
      "source": "scan",
      "summary": "Injection markers (unverified → pass)",
      "link": "https://verifymcp.io/servers/com-a2awire-data-cisa-known-exploited-vulnerability-catalog/mcp-data-cisa-known-exploited-vulnerabilities-kevwatch-aedaf3-http#chg-chg_01a0d20a-f4be-71be-8cae-e3ec2a9a23f2"
    },
    {
      "id": "chg_01a0d20a-f4c0-7c59-b36a-5f8037f1655d",
      "kind": "check.reverified",
      "family": "hsts",
      "subject_kind": "check",
      "subject": "hsts",
      "subject_child": "",
      "from_code": "headers.inconclusive",
      "to_code": "headers.hsts_present",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-24",
      "occurred_at": "2026-09-24 06:12:08.281379+00",
      "observed_since": "2026-09-23",
      "source": "scan",
      "summary": "HSTS header (unverified → pass)",
      "link": "https://verifymcp.io/servers/com-a2awire-data-cisa-known-exploited-vulnerability-catalog/mcp-data-cisa-known-exploited-vulnerabilities-kevwatch-aedaf3-http#chg-chg_01a0d20a-f4c0-7c59-b36a-5f8037f1655d"
    },
    {
      "id": "chg_01a0d20a-f4c4-70ef-9557-eeb94f229e81",
      "kind": "server.instructions_changed",
      "family": "",
      "subject_kind": "server",
      "subject": "instructions",
      "subject_child": "",
      "from_code": null,
      "to_code": null,
      "from_value": null,
      "to_value": null,
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-24",
      "occurred_at": "2026-09-24 06:12:08.281379+00",
      "observed_since": "2026-09-22",
      "source": "scan",
      "summary": "The server rewrote its instructions, which are the text every model session reads",
      "link": "https://verifymcp.io/servers/com-a2awire-data-cisa-known-exploited-vulnerability-catalog/mcp-data-cisa-known-exploited-vulnerabilities-kevwatch-aedaf3-http#chg-chg_01a0d20a-f4c4-70ef-9557-eeb94f229e81"
    },
    {
      "id": "chg_01a0cce5-1683-7b12-9837-f0101e90ee6f",
      "kind": "check.unverifiable",
      "family": "auth-oauth",
      "subject_kind": "check",
      "subject": "auth-oauth",
      "subject_child": "",
      "from_code": "auth.none_destructive",
      "to_code": "auth.unreachable",
      "from_value": "fail",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-23",
      "occurred_at": "2026-09-23 06:12:40.474281+00",
      "observed_since": "2026-09-22",
      "source": "scan",
      "summary": "Authorization (fail → unverified)",
      "link": "https://verifymcp.io/servers/com-a2awire-data-cisa-known-exploited-vulnerability-catalog/mcp-data-cisa-known-exploited-vulnerabilities-kevwatch-aedaf3-http#chg-chg_01a0cce5-1683-7b12-9837-f0101e90ee6f"
    },
    {
      "id": "chg_01a0cce5-1684-7f10-be01-b5a695c8d343",
      "kind": "check.unverifiable",
      "family": "tool-safety-injection",
      "subject_kind": "check",
      "subject": "tool-safety-injection",
      "subject_child": "",
      "from_code": "toolsafety.injection_clean",
      "to_code": "toolsafety.unreachable",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-23",
      "occurred_at": "2026-09-23 06:12:40.474281+00",
      "observed_since": "2026-09-22",
      "source": "scan",
      "summary": "Tool safety (pass → unverified)",
      "link": "https://verifymcp.io/servers/com-a2awire-data-cisa-known-exploited-vulnerability-catalog/mcp-data-cisa-known-exploited-vulnerabilities-kevwatch-aedaf3-http#chg-chg_01a0cce5-1684-7f10-be01-b5a695c8d343"
    },
    {
      "id": "chg_01a0cce5-1686-7184-a2f8-92ce13698a66",
      "kind": "check.unverifiable",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.building_history",
      "to_code": "stability.insufficient_history",
      "from_value": "0.67",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-23",
      "occurred_at": "2026-09-23 06:12:40.474281+00",
      "observed_since": "2026-09-22",
      "source": "scan",
      "summary": "Stability (0.67 → unverified)",
      "link": "https://verifymcp.io/servers/com-a2awire-data-cisa-known-exploited-vulnerability-catalog/mcp-data-cisa-known-exploited-vulnerabilities-kevwatch-aedaf3-http#chg-chg_01a0cce5-1686-7184-a2f8-92ce13698a66"
    },
    {
      "id": "chg_01a0cce5-1686-75c6-b05e-67a1b71f42fa",
      "kind": "check.verdict",
      "family": "transport",
      "subject_kind": "check",
      "subject": "transport",
      "subject_child": "",
      "from_code": "transport.verified",
      "to_code": "transport.unreachable",
      "from_value": "pass",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "transport": "streamable-http"
      },
      "occurred_on": "2026-09-23",
      "occurred_at": "2026-09-23 06:12:40.474281+00",
      "observed_since": "2026-09-22",
      "source": "scan",
      "summary": "Transport (pass → fail)",
      "link": "https://verifymcp.io/servers/com-a2awire-data-cisa-known-exploited-vulnerability-catalog/mcp-data-cisa-known-exploited-vulnerabilities-kevwatch-aedaf3-http#chg-chg_01a0cce5-1686-75c6-b05e-67a1b71f42fa"
    },
    {
      "id": "chg_01a0cce5-1688-773d-af05-5301858a09c9",
      "kind": "check.unverifiable",
      "family": "hsts",
      "subject_kind": "check",
      "subject": "hsts",
      "subject_child": "",
      "from_code": "headers.hsts_present",
      "to_code": "headers.inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-23",
      "occurred_at": "2026-09-23 06:12:40.474281+00",
      "observed_since": "2026-09-22",
      "source": "scan",
      "summary": "HSTS header (pass → unverified)",
      "link": "https://verifymcp.io/servers/com-a2awire-data-cisa-known-exploited-vulnerability-catalog/mcp-data-cisa-known-exploited-vulnerabilities-kevwatch-aedaf3-http#chg-chg_01a0cce5-1688-773d-af05-5301858a09c9"
    },
    {
      "id": "chg_01a0cce5-168a-7153-8f8c-818e96442aea",
      "kind": "capture.status_changed",
      "family": "",
      "subject_kind": "server",
      "subject": "capture",
      "subject_child": "",
      "from_code": null,
      "to_code": null,
      "from_value": "verified",
      "to_value": "unreachable",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "to": "unreachable",
        "from": "verified"
      },
      "occurred_on": "2026-09-23",
      "occurred_at": "2026-09-23 06:12:40.474281+00",
      "observed_since": "2026-09-22",
      "source": "scan",
      "summary": "Endpoint reachability (reachable → unreachable)",
      "link": "https://verifymcp.io/servers/com-a2awire-data-cisa-known-exploited-vulnerability-catalog/mcp-data-cisa-known-exploited-vulnerabilities-kevwatch-aedaf3-http#chg-chg_01a0cce5-168a-7153-8f8c-818e96442aea"
    },
    {
      "id": "chg_01a0b84c-1185-7535-af31-c964723185cc",
      "kind": "check.reverified",
      "family": "tool-safety-manipulation",
      "subject_kind": "check",
      "subject": "tool-safety-manipulation",
      "subject_child": "",
      "from_code": "toolsafety.manipulation_unjudged",
      "to_code": "toolsafety.manipulation_clean",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "units": "17",
        "judged": "17"
      },
      "occurred_on": "2026-09-19",
      "occurred_at": "2026-09-19 06:13:07.97296+00",
      "observed_since": "2026-09-18",
      "source": "scan",
      "summary": "Judged manipulation (unverified → pass)",
      "link": "https://verifymcp.io/servers/com-a2awire-data-cisa-known-exploited-vulnerability-catalog/mcp-data-cisa-known-exploited-vulnerabilities-kevwatch-aedaf3-http#chg-chg_01a0b84c-1185-7535-af31-c964723185cc"
    },
    {
      "id": "chg_01a0b84c-1187-79cc-8bfc-46d6a0299f79",
      "kind": "tool.description_changed",
      "family": "",
      "subject_kind": "tool",
      "subject": "a2awire_guide",
      "subject_child": "",
      "from_code": null,
      "to_code": null,
      "from_value": null,
      "to_value": null,
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "tool": "a2awire_guide"
      },
      "occurred_on": "2026-09-19",
      "occurred_at": "2026-09-19 06:13:07.97296+00",
      "observed_since": "2026-09-18",
      "source": "scan",
      "summary": "Tool “a2awire_guide” rewrote its description, which is the text the model reads",
      "link": "https://verifymcp.io/servers/com-a2awire-data-cisa-known-exploited-vulnerability-catalog/mcp-data-cisa-known-exploited-vulnerabilities-kevwatch-aedaf3-http#chg-chg_01a0b84c-1187-79cc-8bfc-46d6a0299f79"
    },
    {
      "id": "chg_01a0b84c-1187-7ee9-8a6b-2981be52844c",
      "kind": "server.instructions_changed",
      "family": "",
      "subject_kind": "server",
      "subject": "instructions",
      "subject_child": "",
      "from_code": null,
      "to_code": null,
      "from_value": null,
      "to_value": null,
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-19",
      "occurred_at": "2026-09-19 06:13:07.97296+00",
      "observed_since": "2026-09-18",
      "source": "scan",
      "summary": "The server rewrote its instructions, which are the text every model session reads",
      "link": "https://verifymcp.io/servers/com-a2awire-data-cisa-known-exploited-vulnerability-catalog/mcp-data-cisa-known-exploited-vulnerabilities-kevwatch-aedaf3-http#chg-chg_01a0b84c-1187-7ee9-8a6b-2981be52844c"
    },
    {
      "id": "chg_01a0b325-a39e-7639-8cf1-db945e8b4f17",
      "kind": "check.unverifiable",
      "family": "tool-safety-manipulation",
      "subject_kind": "check",
      "subject": "tool-safety-manipulation",
      "subject_child": "",
      "from_code": "toolsafety.manipulation_clean",
      "to_code": "toolsafety.manipulation_unjudged",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "units": "17",
        "judged": "16",
        "reason": "partially_judged"
      },
      "occurred_on": "2026-09-18",
      "occurred_at": "2026-09-18 06:13:02.427266+00",
      "observed_since": "2026-09-17",
      "source": "scan",
      "summary": "Judged manipulation (pass → unverified)",
      "link": "https://verifymcp.io/servers/com-a2awire-data-cisa-known-exploited-vulnerability-catalog/mcp-data-cisa-known-exploited-vulnerabilities-kevwatch-aedaf3-http#chg-chg_01a0b325-a39e-7639-8cf1-db945e8b4f17"
    },
    {
      "id": "chg_01a0b325-a3a2-7b68-8bc2-a883c6b7a79f",
      "kind": "server.instructions_changed",
      "family": "",
      "subject_kind": "server",
      "subject": "instructions",
      "subject_child": "",
      "from_code": null,
      "to_code": null,
      "from_value": null,
      "to_value": null,
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-18",
      "occurred_at": "2026-09-18 06:13:02.427266+00",
      "observed_since": "2026-09-17",
      "source": "scan",
      "summary": "The server rewrote its instructions, which are the text every model session reads",
      "link": "https://verifymcp.io/servers/com-a2awire-data-cisa-known-exploited-vulnerability-catalog/mcp-data-cisa-known-exploited-vulnerabilities-kevwatch-aedaf3-http#chg-chg_01a0b325-a3a2-7b68-8bc2-a883c6b7a79f"
    },
    {
      "id": "chg_01a089f1-794c-71fb-a05a-29f7abab33d8",
      "kind": "tool.description_changed",
      "family": "",
      "subject_kind": "tool",
      "subject": "a2awire_guide",
      "subject_child": "",
      "from_code": null,
      "to_code": null,
      "from_value": null,
      "to_value": null,
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "tool": "a2awire_guide"
      },
      "occurred_on": "2026-09-10",
      "occurred_at": "2026-09-10 06:11:38.772015+00",
      "observed_since": "2026-09-09",
      "source": "scan",
      "summary": "Tool “a2awire_guide” rewrote its description, which is the text the model reads",
      "link": "https://verifymcp.io/servers/com-a2awire-data-cisa-known-exploited-vulnerability-catalog/mcp-data-cisa-known-exploited-vulnerabilities-kevwatch-aedaf3-http#chg-chg_01a089f1-794c-71fb-a05a-29f7abab33d8"
    },
    {
      "id": "chg_01a07fa6-2b56-7391-945d-84972dc011d9",
      "kind": "tool.description_changed",
      "family": "",
      "subject_kind": "tool",
      "subject": "data_session_open",
      "subject_child": "",
      "from_code": null,
      "to_code": null,
      "from_value": null,
      "to_value": null,
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "tool": "data_session_open"
      },
      "occurred_on": "2026-09-08",
      "occurred_at": "2026-09-08 06:13:11.394856+00",
      "observed_since": "2026-09-07",
      "source": "scan",
      "summary": "Tool “data_session_open” rewrote its description, which is the text the model reads",
      "link": "https://verifymcp.io/servers/com-a2awire-data-cisa-known-exploited-vulnerability-catalog/mcp-data-cisa-known-exploited-vulnerabilities-kevwatch-aedaf3-http#chg-chg_01a07fa6-2b56-7391-945d-84972dc011d9"
    },
    {
      "id": "chg_01a07030-719c-77a5-b9d2-c595380c215e",
      "kind": "tool.description_changed",
      "family": "",
      "subject_kind": "tool",
      "subject": "a2awire_guide",
      "subject_child": "",
      "from_code": null,
      "to_code": null,
      "from_value": null,
      "to_value": null,
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "tool": "a2awire_guide"
      },
      "occurred_on": "2026-09-05",
      "occurred_at": "2026-09-05 06:10:17.825045+00",
      "observed_since": "2026-09-04",
      "source": "scan",
      "summary": "Tool “a2awire_guide” rewrote its description, which is the text the model reads",
      "link": "https://verifymcp.io/servers/com-a2awire-data-cisa-known-exploited-vulnerability-catalog/mcp-data-cisa-known-exploited-vulnerabilities-kevwatch-aedaf3-http#chg-chg_01a07030-719c-77a5-b9d2-c595380c215e"
    }
  ],
  "days": [
    {
      "date": "2026-09-25",
      "total": 75,
      "delta": 1,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-24",
      "total": 74,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 9
    },
    {
      "date": "2026-09-23",
      "total": 74,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 9
    },
    {
      "date": "2026-09-22",
      "total": 74,
      "delta": 1,
      "tracked": true,
      "explained": false,
      "beyond_event_horizon": false,
      "attribution": {
        "category": "Stability & Change Management",
        "from": 63,
        "to": 67,
        "delta": 4,
        "others": [],
        "accrual": {
          "code": "stability.building_history",
          "from_days": 19,
          "to_days": 20
        },
        "partial": false,
        "compared_to": "2026-09-21",
        "summary": "No change was recorded against any check on this day. Stability & Change Management went from 63 to 67. That category is still filling its 30-day observation window: 19 days of observed history at the previous scan, 20 at this one. The score rises as the window fills, whether or not the server changes."
      },
      "event_count": 0
    },
    {
      "date": "2026-09-20",
      "total": 73,
      "delta": 1,
      "tracked": true,
      "explained": false,
      "beyond_event_horizon": false,
      "attribution": {
        "category": "Stability & Change Management",
        "from": 57,
        "to": 60,
        "delta": 3,
        "others": [],
        "accrual": {
          "code": "stability.building_history",
          "from_days": 17,
          "to_days": 18
        },
        "partial": false,
        "compared_to": "2026-09-19",
        "summary": "No change was recorded against any check on this day. Stability & Change Management went from 57 to 60. That category is still filling its 30-day observation window: 17 days of observed history at the previous scan, 18 at this one. The score rises as the window fills, whether or not the server changes."
      },
      "event_count": 0
    },
    {
      "date": "2026-09-19",
      "total": 72,
      "delta": 11,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 4
    },
    {
      "date": "2026-09-18",
      "total": 61,
      "delta": -11,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 3
    },
    {
      "date": "2026-09-17",
      "total": 72,
      "delta": 1,
      "tracked": true,
      "explained": false,
      "beyond_event_horizon": false,
      "attribution": {
        "category": "Stability & Change Management",
        "from": 47,
        "to": 50,
        "delta": 3,
        "others": [],
        "accrual": {
          "code": "stability.building_history",
          "from_days": 14,
          "to_days": 15
        },
        "partial": false,
        "compared_to": "2026-09-16",
        "summary": "No change was recorded against any check on this day. Stability & Change Management went from 47 to 50. That category is still filling its 30-day observation window: 14 days of observed history at the previous scan, 15 at this one. The score rises as the window fills, whether or not the server changes."
      },
      "event_count": 0
    }
  ]
}