MVS (Managed Vulnerability Service) API — Recent Changes
Customer-relevant changes to MVS (Managed Vulnerability Service) API endpoints and schemas from the past 6 months. Dates below are when each change was committed, not necessarily when it reached production — release to production may lag as it rolls through our int → uat → production pipeline.
| Date | Version | Type | Change |
|---|---|---|---|
| 2026-09-24 | 1.16.0 | Added | Added six endpoints: GET /assets/{asset_id}/confidence and GET /assets-confidence (asset confidence scores), GET /assets/{asset_id}/scores (asset criticality/risk/exposure scores), GET /software-to-patch and GET /assets-to-patch (ranked patch-priority lists), and GET /cisa-kev (vulnerabilities on CISA's Known Exploited Vulnerabilities catalog). |
| 2026-09-15 | 1.15.0 | Added | Added an optional tenant_code query parameter to all list and detail endpoints, letting a partner organization query MVS data on behalf of a tenant organization it directly manages. |
| 2026-09-02 | 1.14.0 | Added | Documented two previously undocumented endpoints: GET /assets/{asset_id}/vulnerabilities and GET /assets/{asset_id}/vulnerabilities/{vulnerability_id}. |
| 2026-09-02 | 1.14.0 | Fixed | Corrected inaccuracies in the API reference, including clarifying that MVS endpoints do not perform a separate subscription check, and splitting the last_scanned field out of the shared list response schema (it only appears on GET /vulnerabilities responses). |
| 2026-08-26 | 1.13.0 | Added | Added support for page/per_page query parameters as an alternative to limit/offset for pagination on all list endpoints. |