<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: CyberMax</title>
    <description>The latest articles on DEV Community by CyberMax (@cybermax).</description>
    <link>https://dev.to/cybermax</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4176076%2Fd038854b-a010-4e24-89dc-26373bb38f77.png</url>
      <title>DEV Community: CyberMax</title>
      <link>https://dev.to/cybermax</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/cybermax"/>
    <language>en</language>
    <item>
      <title>Which CVEs to patch first this week (KEV + EPSS, 27 Sep 2026)</title>
      <dc:creator>CyberMax</dc:creator>
      <pubDate>Sun, 11 Oct 2026 14:50:22 +0000</pubDate>
      <link>https://dev.to/cybermax/which-cves-to-patch-first-this-week-kev-epss-27-sep-2026-5bfe</link>
      <guid>https://dev.to/cybermax/which-cves-to-patch-first-this-week-kev-epss-27-sep-2026-5bfe</guid>
      <description>&lt;p&gt;There are more than 380,000 CVEs with an EPSS score and no team patches them all. The two free signals that cut the list down fastest are &lt;strong&gt;CISA's Known Exploited Vulnerabilities (KEV) catalog&lt;/strong&gt; (confirmed exploitation in the wild) and &lt;strong&gt;FIRST's EPSS&lt;/strong&gt; (the probability of exploitation activity in the next 30 days). This week's list, and a repeatable way to build it.&lt;/p&gt;

&lt;h2&gt;
  
  
  This week: 17 new exploited CVEs, 3-day deadlines
&lt;/h2&gt;

&lt;p&gt;Between 14 and 25 September 2026 CISA added 17 CVEs to KEV (catalog version 2026.09.25, 1,726 CVEs in total). All 17 carry a &lt;strong&gt;federal due date three days after they were added&lt;/strong&gt; (the latest due date is 28 September). Sorted by EPSS:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;CVE&lt;/th&gt;
&lt;th&gt;Vendor / product&lt;/th&gt;
&lt;th&gt;Added&lt;/th&gt;
&lt;th&gt;Federal due&lt;/th&gt;
&lt;th&gt;EPSS&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;CVE-2026-71362&lt;/td&gt;
&lt;td&gt;Adobe Commerce and Magento&lt;/td&gt;
&lt;td&gt;24 Sep&lt;/td&gt;
&lt;td&gt;27 Sep&lt;/td&gt;
&lt;td&gt;87.5%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;CVE-2026-76461&lt;/td&gt;
&lt;td&gt;Cisco Secure Email Gateway&lt;/td&gt;
&lt;td&gt;14 Sep&lt;/td&gt;
&lt;td&gt;17 Sep&lt;/td&gt;
&lt;td&gt;28.3%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;CVE-2026-93616&lt;/td&gt;
&lt;td&gt;Check Point (multiple products)&lt;/td&gt;
&lt;td&gt;22 Sep&lt;/td&gt;
&lt;td&gt;25 Sep&lt;/td&gt;
&lt;td&gt;19.7%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;CVE-2026-87902&lt;/td&gt;
&lt;td&gt;WordPress Core (remote file inclusion)&lt;/td&gt;
&lt;td&gt;25 Sep&lt;/td&gt;
&lt;td&gt;28 Sep&lt;/td&gt;
&lt;td&gt;18.2%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;CVE-2026-76460&lt;/td&gt;
&lt;td&gt;Cisco Identity Services Engine&lt;/td&gt;
&lt;td&gt;16 Sep&lt;/td&gt;
&lt;td&gt;19 Sep&lt;/td&gt;
&lt;td&gt;14.0%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;CVE-2025-39682&lt;/td&gt;
&lt;td&gt;Linux Kernel&lt;/td&gt;
&lt;td&gt;18 Sep&lt;/td&gt;
&lt;td&gt;21 Sep&lt;/td&gt;
&lt;td&gt;2.9%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;CVE-2026-7273&lt;/td&gt;
&lt;td&gt;Zyxel GS1900 switches&lt;/td&gt;
&lt;td&gt;21 Sep&lt;/td&gt;
&lt;td&gt;24 Sep&lt;/td&gt;
&lt;td&gt;2.5%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;CVE-2026-94127&lt;/td&gt;
&lt;td&gt;F5 BIG-IP APM&lt;/td&gt;
&lt;td&gt;22 Sep&lt;/td&gt;
&lt;td&gt;25 Sep&lt;/td&gt;
&lt;td&gt;2.2%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;CVE-2026-65660&lt;/td&gt;
&lt;td&gt;Microsoft SharePoint&lt;/td&gt;
&lt;td&gt;25 Sep&lt;/td&gt;
&lt;td&gt;28 Sep&lt;/td&gt;
&lt;td&gt;2.1%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;CVE-2026-67279&lt;/td&gt;
&lt;td&gt;MikroTik RouterOS&lt;/td&gt;
&lt;td&gt;25 Sep&lt;/td&gt;
&lt;td&gt;28 Sep&lt;/td&gt;
&lt;td&gt;1.0%&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The other seven (Arista VeloCloud Orchestrator, a second Check Point CVE, two more Linux kernel CVEs, WSO2, Acronis Backup and Google Pixel) score under 1.1%. They are still exploited; EPSS only tells you where mass exploitation is most likely.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;EPSS of the CVEs CISA added 14–25 Sep 2026&lt;/strong&gt;&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;&lt;/th&gt;
&lt;th&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Adobe Commerce&lt;/td&gt;
&lt;td&gt;87.5%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Cisco Email Gateway&lt;/td&gt;
&lt;td&gt;28.3%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Check Point&lt;/td&gt;
&lt;td&gt;19.7%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;WordPress Core&lt;/td&gt;
&lt;td&gt;18.2%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Cisco ISE&lt;/td&gt;
&lt;td&gt;14.0%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Linux Kernel&lt;/td&gt;
&lt;td&gt;2.9%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Zyxel GS1900&lt;/td&gt;
&lt;td&gt;2.5%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;F5 BIG-IP APM&lt;/td&gt;
&lt;td&gt;2.2%&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;&lt;em&gt;FIRST EPSS scores dated 27 Sep 2026: the estimated chance of exploitation activity in the next 30 days. Top 8 of the 17 additions.&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  The order to patch in
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;In KEV and internet-facing:&lt;/strong&gt; Adobe Commerce/Magento, WordPress core, Cisco Secure Email Gateway, Check Point gateways, F5 BIG-IP APM, SharePoint. Exploitation is confirmed and the systems are reachable by anyone.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;In KEV, inside the network:&lt;/strong&gt; Cisco ISE, the Linux kernel CVEs, Zyxel switches, MikroTik routers, Acronis Backup.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Not in KEV but EPSS above 10%:&lt;/strong&gt; the early-warning list. 17,267 CVEs have an EPSS of 10% or more today, and only 1,274 of them are in KEV. Run your scanner output through both signals and the gap is where the next KEV entries usually come from.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Everything else by CVSS and exposure&lt;/strong&gt;, on your normal patch cycle.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;strong&gt;Try it: CVEs added to KEV in the last 14 days (free, no key):&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl &lt;span class="s1"&gt;'https://kevscope-api.cybermaxtools.com/api/kev/recent?days=14'&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Why KEV plus EPSS beats CVSS alone
&lt;/h2&gt;

&lt;p&gt;CVSS rates how bad a flaw &lt;em&gt;could&lt;/em&gt; be. It does not say whether anyone is using it. Of the 1,726 KEV entries, 361 are known to be used in ransomware campaigns. Vendor pages show how concentrated the risk is: Microsoft has 389 CVEs in KEV, Cisco 99, Apple 94 and Ivanti 35. See every vendor.&lt;/p&gt;

&lt;h2&gt;
  
  
  Automate it: one call per 20 CVEs
&lt;/h2&gt;

&lt;p&gt;Paste your scanner's CVE list into Kevscope and every CVE comes back with a verdict (&lt;code&gt;act_now&lt;/code&gt;, &lt;code&gt;high&lt;/code&gt;, &lt;code&gt;medium&lt;/code&gt;, &lt;code&gt;low&lt;/code&gt;) and the evidence behind it: KEV status, due date and ransomware use, EPSS score and percentile, CVSS and CISA's SSVC decision points. The rules are public: &lt;code&gt;act_now&lt;/code&gt; means it is in KEV or SSVC says exploitation is active; &lt;code&gt;high&lt;/code&gt; means EPSS of 10% or more, or an automatable CVSS 9+ flaw with a public exploit.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl &lt;span class="s2"&gt;"https://kevscope-api.cybermaxtools.com/api/priority?cve=CVE-2026-71362,CVE-2026-65660"&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The same key works as a remote MCP server, so an AI agent can triage a scan for you.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Kevscope&lt;/strong&gt;: CVE priority API: up to 20 CVEs per call, each with a verdict and the KEV, EPSS, CVSS and SSVC evidence.&lt;/p&gt;

&lt;p&gt;Free: 200 calls a day, no key and no card. Paid keys from $19/month (10,000 calls), or $5 pay as you go (2,000, no expiry).&lt;/p&gt;

&lt;p&gt;&lt;a href="https://cybermaxtools.com/store/kevscope-api/?utm_source=devto&amp;amp;utm_medium=article&amp;amp;utm_campaign=2026-09-27-blog-which-cves-to-patch-first-this-week" rel="noopener noreferrer"&gt;See Kevscope plans and pricing&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Published prices on 27 September 2026: OpenCVE Starter is €19/month and Pro €49/month; Vulners Basic is $600/month. Kevscope is free for 200 calls a day, then $19/month for 10,000 calls. Prefer a report to an API? The Exploited Vulnerabilities Brief lands every Monday.&lt;/p&gt;

&lt;p&gt;Sources: &lt;a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" rel="noopener noreferrer"&gt;CISA KEV catalog&lt;/a&gt;, &lt;a href="https://www.first.org/epss/" rel="noopener noreferrer"&gt;FIRST EPSS&lt;/a&gt; scores dated 27 Sep 2026, &lt;a href="https://nvd.nist.gov/" rel="noopener noreferrer"&gt;NIST NVD&lt;/a&gt;.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Published automatically by CyberMax. Every number above comes from the linked public data; nothing is estimated.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>cve</category>
      <category>api</category>
      <category>devops</category>
    </item>
    <item>
      <title>How to check any US tariff rate by HTS code (2026)</title>
      <dc:creator>CyberMax</dc:creator>
      <pubDate>Sat, 10 Oct 2026 23:00:28 +0000</pubDate>
      <link>https://dev.to/cybermax/how-to-check-any-us-tariff-rate-by-hts-code-2026-2pe7</link>
      <guid>https://dev.to/cybermax/how-to-check-any-us-tariff-rate-by-hts-code-2026-2pe7</guid>
      <description>&lt;p&gt;The US duty on an imported product is set by its 10-digit &lt;strong&gt;HTS code&lt;/strong&gt; (Harmonized Tariff Schedule of the United States). For products of China, a second layer applies on top: the &lt;strong&gt;Section 301&lt;/strong&gt; tariffs, which add 7.5% or 25% to most codes. This guide shows how to get both numbers for any code, from the official source, in under a minute.&lt;/p&gt;

&lt;h2&gt;
  
  
  The short answer
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;Find the code: search the HTS by product words (for example "coffee maker").&lt;/li&gt;
&lt;li&gt;Read the &lt;strong&gt;General&lt;/strong&gt; rate column for that 8-digit line. That is the normal (MFN) duty.&lt;/li&gt;
&lt;li&gt;Check Chapter 99 U.S. note 20 to see if the code is on a Section 301 list. If it is, products of China pay the list's extra duty as well.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Doing step 3 by hand is the slow part: note 20 is a long list of codes spread over several lists, exclusions and later increases. The rest of this guide does all three steps with real data.&lt;/p&gt;

&lt;h2&gt;
  
  
  Step 1: find the HTS code
&lt;/h2&gt;

&lt;p&gt;Search the product words. A search for &lt;strong&gt;coffee maker&lt;/strong&gt; in the current schedule (2026 Revision 19, in effect from 15 September 2026) returns heading 8516, subheading &lt;strong&gt;8516.71.00 "Coffee or tea makers"&lt;/strong&gt;, with statistical suffixes such as 8516.71.00.20 "Automatic drip and pump type".&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Try it: look up 8516.71.00 (free, no key):&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl &lt;span class="s1"&gt;'https://dutyfinch.cybermaxtools.com/api/hts?code=8516.71.00'&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Step 2: read the general duty rate
&lt;/h2&gt;

&lt;p&gt;For 8516.71.00 the official rates are:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Column&lt;/th&gt;
&lt;th&gt;Rate&lt;/th&gt;
&lt;th&gt;Who pays it&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;General (MFN)&lt;/td&gt;
&lt;td&gt;3.7%&lt;/td&gt;
&lt;td&gt;most countries, including China&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Special&lt;/td&gt;
&lt;td&gt;Free&lt;/td&gt;
&lt;td&gt;free-trade partners (AU, CL, CO, KR, SG and others listed on the line)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Column 2&lt;/td&gt;
&lt;td&gt;40%&lt;/td&gt;
&lt;td&gt;the few countries without normal trade relations&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Across the whole schedule, 38% of the 11,414 rated tariff lines are duty-free at the general rate, and only 107 lines are above 25%:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;US tariff lines by general (MFN) duty rate&lt;/strong&gt;&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;&lt;/th&gt;
&lt;th&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Free&lt;/td&gt;
&lt;td&gt;4,315&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;0-5%&lt;/td&gt;
&lt;td&gt;2,678&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;5-10%&lt;/td&gt;
&lt;td&gt;2,268&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;10-25%&lt;/td&gt;
&lt;td&gt;810&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;over 25%&lt;/td&gt;
&lt;td&gt;107&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;specific or compound&lt;/td&gt;
&lt;td&gt;1,236&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;&lt;em&gt;11,414 tariff lines with a rate in the USITC HTS 2026 Revision 19. Specific or compound = a rate per unit (e.g. ¢/kg).&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Step 3: check Section 301 for products of China
&lt;/h2&gt;

&lt;p&gt;8516.71.00 is on &lt;strong&gt;List 4A&lt;/strong&gt; (heading 9903.88.15), so a coffee maker made in China pays &lt;strong&gt;3.7% + 7.5% = 11.2%&lt;/strong&gt; of its customs value. The same coffee maker made in Vietnam pays 3.7%.&lt;/p&gt;

&lt;p&gt;Section 301 is not a niche issue: 10,003 of the 11,414 rated lines (88%) are on a list that is in effect today. The lists differ a lot in size:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;HTS codes on each Section 301 China list&lt;/strong&gt;&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;&lt;/th&gt;
&lt;th&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;List 1 (+25%)&lt;/td&gt;
&lt;td&gt;856&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;List 2 (+25%)&lt;/td&gt;
&lt;td&gt;283&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;List 3 (+25%)&lt;/td&gt;
&lt;td&gt;5,906&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;List 4A (+7.5%)&lt;/td&gt;
&lt;td&gt;2,958&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;4B (+15%, suspended)&lt;/td&gt;
&lt;td&gt;546&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;&lt;em&gt;Codes named in HTS Chapter 99, U.S. note 20. List 4B has been suspended since December 2019, so it is not collected.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Some codes also have &lt;strong&gt;product exclusions&lt;/strong&gt; (currently running to 9 November 2026) or a &lt;strong&gt;2024 four-year-review increase&lt;/strong&gt; with its own start date, such as electric vehicles (+100%) and semiconductors (+50%). Always read the exclusion text: it often covers only one described product inside a code.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Other duties can apply too: Section 232 (steel, aluminium and others), antidumping and countervailing duties, and other Chapter 99 measures. Confirm any classification with CBP or a licensed customs broker before you import.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  The 2026 US–China tariff cuts
&lt;/h2&gt;

&lt;p&gt;On 26 September 2026 the US and Chinese governments announced plans to lower tariffs on about $30 billion of "non-sensitive" goods in each direction; press reports name small appliances, toys and decorations. As of 27 September the HTS code lists and effective dates are &lt;strong&gt;not published&lt;/strong&gt;. When USTR publishes them in the Federal Register, every affected code changes at once, which is exactly when a manual spreadsheet goes stale.&lt;/p&gt;

&lt;h2&gt;
  
  
  Do it by API (and get told when a rate changes)
&lt;/h2&gt;

&lt;p&gt;If you check more than a handful of codes, or you quote landed costs to customers, the lookups belong in code. Dutyfinch answers &lt;code&gt;GET /api/hts?code=8516.71.00&lt;/code&gt; with the description path, the three rate columns, the Section 301 list, exclusions with end dates and a flag for the 2026 US–China reduction list. Keyword search covers all 26,246 HTS codes, and the same key works as a remote MCP server for AI agents.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl &lt;span class="s2"&gt;"https://dutyfinch.cybermaxtools.com/api/hts?code=8516.71.00"&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Dutyfinch&lt;/strong&gt;: US tariff lookup API and MCP server: official duty rates, Section 301 China status and the 2026 US–China reduction flag.&lt;/p&gt;

&lt;p&gt;Free: 50 calls a day, no key and no card. Paid keys from $19/month (2,500 calls), or $5 pay as you go (500, no expiry).&lt;/p&gt;

&lt;p&gt;&lt;a href="https://cybermaxtools.com/store/dutyfinch-api/?utm_source=devto&amp;amp;utm_medium=article&amp;amp;utm_campaign=2026-09-27-blog-check-us-tariff-rate-by-hts-code" rel="noopener noreferrer"&gt;See Dutyfinch plans and pricing&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  How it compares
&lt;/h2&gt;

&lt;p&gt;Published prices on 27 September 2026: US Tariff Rates Pro is $49/month for 5,000 requests, Global Tariff Rates Pro is $49/month, and Dutify Plus is $75/month for 500 tariff lookups. Dutyfinch has 50 free calls a day with no key, Importer at $19/month for 2,500 calls, Broker at $49/month for 7,500 calls plus webhook alerts on 100 watched codes. See the full comparisons and every chapter's rates on the tariff pages, for example chapter 85 (electrical machinery).&lt;/p&gt;

&lt;p&gt;Sources: &lt;a href="https://hts.usitc.gov/" rel="noopener noreferrer"&gt;USITC Harmonized Tariff Schedule&lt;/a&gt; 2026 Revision 19 and HTS Chapter 99 U.S. notes 20 and 31; &lt;a href="https://www.federalregister.gov/" rel="noopener noreferrer"&gt;Federal Register&lt;/a&gt; (USTR notices, checked daily).&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Published automatically by CyberMax. Every number above comes from the linked public data; nothing is estimated.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>tariffs</category>
      <category>api</category>
      <category>ecommerce</category>
      <category>python</category>
    </item>
  </channel>
</rss>
