- Subscribe to RSS Feed
- Mark as New
- Mark as Read
- Bookmark
- Subscribe
- Printer Friendly Page
- Report Inappropriate Content
Two dates first, because they are the part you have to act on. On September 3, 2026, AP5m becomes the mandatory quarterly patching target for commercial Australia instances. In October 2026, ZP12m does the same for Zurich.
The 'm' patch replaces the full patch, and it carries something the full patch never did: the latest ServiceNow AI applications and the dependencies they need. If you run patching for a commercial instance, that is the change to plan around. What follows is what it means in practice, what it does not change, and why the bundling is worth having.
In this post
What Is Changing
Until now, patching and AI application currency were two separate jobs. Functional and security fixes arrived through the patch release. AI applications were updated separately through the ServiceNow Store, on their own schedule, with their own planning, their own testing window, and their own change record.
That separation did not work well. It doubled the coordination effort for the same instance, and it let the platform version and the application version drift apart, which is where compatibility problems start.
The 'm' patch closes that gap. A single patch release now bundles four things:
- Functional fixes
- Security fixes
- The latest ServiceNow AI applications
- Required AI application dependencies
As a result, the 'm' patch replaces the full patch as the quarterly patching target for commercial instances. The pattern will feel familiar: it is how the major mobile platforms already ship, where the operating system update and the first party applications that depend on it arrive together, tested as one thing, rather than as a sequence you have to assemble yourself.
Scope: This applies to commercial instances. Regulated market customers continue following their existing patching process and will not be updated to 'm' releases.
Why This Matters
Reduced operational overhead. Every separate AI application update is its own cycle of planning, testing, approval and deployment. Folding those updates into the patch you were already going to apply removes a workstream rather than adding one. You keep the instance current using the change process you already run, on a calendar you already own.
Faster access to innovation. New AI capability now reaches your instance on the regular patch cycle instead of waiting for a separate Store activity to be scheduled. If your AI roadmap has been gated on finding a window to update applications, that gate is gone.
Improved application compatibility. Shipping AI applications and their dependencies alongside the platform version keeps them aligned by construction. Fewer version mismatches, fewer surprises after an upgrade, and fewer tickets that turn out to be a drift problem rather than a defect.
"The 'm' patch does not add a step to your quarterly cycle. It removes one."
Where 'm' Patches Fit
The layered approach has not changed. ServiceNow continues to deliver updates in layers, each designed to balance innovation, stability, and security.
Software Releases
A multilayer approach to value and security
1. Family Release
New features, fixes, and improvements with each family release.
2. New 'm' Patch · your quarterly target
Fixes for existing features, Sev 1 and Sev 2 security fixes, plus the latest compatible updates for installed AI Applications.
3. Monthly Security Patches ('a' and 'b')
Sev 1 and Sev 2 security fixes, plus critical availability and reliability fixes.
4. Weekly Security Hot Fixes ('w')
Sev 0 and Sev 1 security issues, the critical and safest subset of the monthly patches.
Each layer sits on top of the one containing it. The 'm' patch is the only layer that carries AI application updates.
The three maintenance layers sit on top of the family release, each on its own cadence. The 'm' patch slots into the quarterly layer.
| Update Type | Purpose | Cadence |
|---|---|---|
| 'm' Patches | Functional fixes, security fixes, and AI application updates | Quarterly target, released monthly |
| Security Patches (a/b releases) | Security maintenance updates | Monthly |
| Security Hot Fixes | Critical security protections | Weekly |
Important: Weekly security hot fixes and monthly security patches are not replaced. They continue as delivered today and remain an essential layer of your security posture alongside the new 'm' patch strategy.
Timeline and Key Milestones
The transition to quarterly 'm' patching targets follows the milestones below.
| Date | Milestone |
|---|---|
| July 2026 | AP4m and ZP11m released as optional patches. |
| August 31, 2026 | Monthly program updates communicated. |
| September 3, 2026 | Targeting changes move to AP5m. |
| September 3, 2026 | AP5m becomes the quarterly patching target for Australia instances. |
| October 2026 | ZP12m becomes the quarterly patching target for Zurich instances. |
Key Takeaways
- One patch replaces two workstreams. The quarterly patch and the separate Store activity for AI applications become a single event. The functional and security fixes you already test for are unchanged; the AI application updates are what is newly included, and they arrive already matched to the platform version rather than needing to be reconciled against it.
- Your security cadence is untouched. Weekly hot fixes and monthly a/b security patches continue exactly as they are. Nothing about the 'm' patch changes how quickly a critical security protection reaches your instance, and nothing about it lets you defer that layer.
- Only installed applications are affected. The 'm' patch updates an AI application if it is already on your instance and a newer version exists in the release. It does not install applications you have not adopted, so the patch does not widen your footprint on its own.
Getting Started
If you are preparing your instances for the September and October targets, the sequence below is a reasonable order to work through.
- Confirm which process applies to you. Commercial instances move to the 'm' patch as the quarterly target. Regulated market instances stay on the existing patching process, so confirm your classification before planning anything else.
- Identify your release family and date. Australia instances target AP5m from September 3, 2026. Zurich instances target ZP12m from October 2026. Those are two different windows and two different change records.
- Open Update Center. Review which AI applications will be updated on your instance and which dependencies come with them. This is the fastest way to see the real scope for your environment rather than the general case.
- Read the application list in the release note. Compare it against what you have installed, and give application owners advance notice of anything in their area that will move.
- Plan your test pass around the AI applications. Functional and security fixes you already know how to validate. The AI application updates are the new variable in this patch, so weight your regression effort accordingly.
- Leave your weekly security cadence alone. Hot fixes and monthly a/b patches continue independently of the quarterly target and should not be rescheduled around it.
Frequently Asked Questions
Which applications are included in an 'm' release?
Each 'm' patch release note includes a list of the applications contained in that distribution. You can also use Update Center to review which applications will be updated on your instance specifically.
Which of my applications will be updated?
If an AI application is installed on your instance and a newer version is available, the 'm' patch will update that application along with any required dependencies.
Does the 'm' patch replace the full patch?
Yes. The 'm' patch replaces the full patch as the mandatory quarterly patching target for commercial instances.
Does this replace weekly security patches?
No. Weekly security patches continue to be delivered and remain an additional layer of protection alongside monthly 'm' patch releases.
What about regulated market instances?
Regulated market customers continue following their existing patching process and will not be updated to 'm' releases.
Resources
- KB3141691: What is an "m" Patch?
- KB3146385: Weekly Security Hot Fixes
- KB0696901: ServiceNow Patching Program FAQs
- KB0541128: Managing ServiceNow Instance Upgrades
- KB0995477: Upgrade Planning and Best Practices
Stay Ahead of the Next Patch
Follow the Upgrades and Patching community for monthly program updates, targeting changes, and guidance as the 'm' patch strategy rolls forward.
Already applied AP4m or ZP11m as an optional patch? Tell us how the testing cycle compared to a full patch in the comments below. I read every one.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.