MVS (Managed Vulnerability Service) API — Recent Changes

Customer-relevant changes to MVS (Managed Vulnerability Service) API endpoints and schemas from the past 6 months. Dates below are when each change was committed, not necessarily when it reached production — release to production may lag as it rolls through our int → uat → production pipeline.

DateVersionTypeChange
2026-09-241.16.0AddedAdded six endpoints: GET /assets/{asset_id}/confidence and GET /assets-confidence (asset confidence scores), GET /assets/{asset_id}/scores (asset criticality/risk/exposure scores), GET /software-to-patch and GET /assets-to-patch (ranked patch-priority lists), and GET /cisa-kev (vulnerabilities on CISA's Known Exploited Vulnerabilities catalog).
2026-09-151.15.0AddedAdded an optional tenant_code query parameter to all list and detail endpoints, letting a partner organization query MVS data on behalf of a tenant organization it directly manages.
2026-09-021.14.0AddedDocumented two previously undocumented endpoints: GET /assets/{asset_id}/vulnerabilities and GET /assets/{asset_id}/vulnerabilities/{vulnerability_id}.
2026-09-021.14.0FixedCorrected inaccuracies in the API reference, including clarifying that MVS endpoints do not perform a separate subscription check, and splitting the last_scanned field out of the shared list response schema (it only appears on GET /vulnerabilities responses).
2026-08-261.13.0AddedAdded support for page/per_page query parameters as an alternative to limit/offset for pagination on all list endpoints.

← Back to MVS API docs