Send daily CISA KEV EPSS risk digests to Slack with OpenAI

Go to Workflow
0 views
Built by V3nom tech V3nom tech
Created on October 03, 2026

Description

Quick Overview
This workflow runs daily to monitor the CISA Known Exploited Vulnerabilities (KEV) catalog for CVEs matching your tech stack, enriches them with FIRST EPSS scores, uses OpenAI to generate a Slack-ready analyst digest, and posts the alert to a Slack channel.

How it works
Runs every day at 8 AM on a schedule.
Downloads the latest CISA Known Exploited Vulnerabilities (KEV) JSON catalog and filters to entries added within your lookback window that match your configured vendors/products.
De-duplicates results by CVE ID across executions so each CVE is only alerted once.
Queries the FIRST EPSS API for each remaining CVE to retrieve exploitation probability data.
Calculates a Critical/High/Medium priority based on ransomware campaign use and EPSS thresholds, then sorts the CVEs by priority and score.
Uses OpenAI to write a Slack-formatted vulnerability digest from the structured CVE data and posts it to your selected Slack channel.

Setup
Add an OpenAI API credential in the OpenAI Chat Model node.
Add a Slack credential and select the target channel in the Post Digest to Slack node.
Update the Configuration values (techStack, lookbackDays, epssHighThreshold) to match your environment, then run a test and activate the workflow.

Nodes Used (5)

Basic LLM Chain
@n8n/n8n-nodes-langchain.chainLlm
Code
n8n-nodes-base.code
HTTP Request
n8n-nodes-base.httpRequest
OpenAI Chat Model
@n8n/n8n-nodes-langchain.lmChatOpenAi
Slack
n8n-nodes-base.slack