Vulnerability Response release notes

  • Release version: Australia
  • Updated July 24, 2026
  • 7 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Vulnerability Response Release Notes - Australia Release

    The ServiceNow Vulnerability Response application enhances collaboration between security and IT teams to expedite remediation of critical vulnerabilities. The Australia release introduces significant updates and integrations that improve vulnerability data accuracy, ingestion efficiency, and system configurability, helping you streamline vulnerability management and improve security posture.

    Show full answer Show less

    Key Features

    • AWS Integration for Security Exposure Management: Supports AWS Inspector and AWS Security Hub, enabling import of host, container vulnerabilities, and misconfigurations for comprehensive exposure management.
    • Central Vulnerability Database (CVDB): Introduces a unified, source-agnostic vulnerability data layer consolidating multiple data sources with configurable priority rules, full source traceability, and enriched vulnerability context.
    • Microsoft SCCM Data Ingestion via JDBC: Allows direct database queries without opening WMI RPC firewall ports, while patch deployment continues through WMI.
    • Invicti Platform Integration: New integration jobs import application lists, scan records, and vulnerability findings, with automatic lifecycle management that deactivates applications and closes related items when removed in Invicti.
    • Wiz Asset Integration Enhancements: Asset integration is now optional and configurable by resource type, simplifying setup and preventing unwanted data imports.
    • Unified Microsoft Defender Integration: Consolidates Defender for Cloud and Threat and Vulnerability Management plugins into one, adding container image vulnerability ingestion and providing a guided migration path.
    • Qualys Integration API Enhancements: Supports newer API versions with additional data fields for improved visibility, and allows selection between API versions to optimize integration.
    • Optimized Tenable.io Compliance Results: Splits ingestion into fixed and open compliance results based on status, improving performance and scalability in large environments.
    • Configuration Enhancements: Adds an “Applies to” field in CI lookup rules to distinguish between Application Vulnerability Response and Vulnerability Response rules, preventing conflicts during background job executions.
    • Remediation Task Rule Execution Modes: Introduces a “Match First” mode that assigns findings to a single remediation task for streamlined processing, alongside the default “Match All” mode.
    • Compensatory Controls Enhancements: New vulnerable items inherit reduced risk ratings from approved compensating controls automatically.
    • Vulnerability Assessment Improvements: Enables CI filtering in assessments, adds Business Application data to AVITs from SBOM results, and rolls down priority updates consistently to related vulnerable items.
    • Background Job Configuration: Allows defining concurrent background jobs via the Vulnerability Manager Workspace Admin console to optimize system resource consumption.

    Important Upgrade and Activation Information

    • Now Assist for Vulnerability Response is being deprecated starting Australia Patch 5; it will be hidden for new instances but remains supported.
    • The product is rebranded under ServiceNow Otto for Unified Security Exposure Management (USEM), with unchanged entitlements.
    • To avoid incompatibilities, customers not upgrading to USEM should use versions below 30.x and appropriate third-party integrations.
    • Vulnerability Response and supported third-party integrations must be installed via the ServiceNow Store.
    • A guided migration is available for moving from deprecated Microsoft Defender plugins to the unified integration.

    What to Expect

    With these updates, ServiceNow customers can expect more efficient and accurate vulnerability data ingestion from multiple sources, improved integration management, and enhanced automation for vulnerability lifecycle and remediation tasks. The Australia release also provides greater flexibility in configuring system resources and integration setups to better fit organizational needs while supporting future scalability and auditability.

    The ServiceNow® Vulnerability Response application brings security and IT together to enable you to remediate your most critical vulnerabilities more quickly and efficiently. Vulnerability Response was enhanced and updated in the Australia release.

    Vulnerability Response highlights for the Australia release

    • The AWS Integration for Security Exposure Management supports integrations with AWS Inspector and AWS Security Hub.
    • The Central Vulnerability Database (CVDB) introduces a source-agnostic vulnerability data layer that consolidates data from multiple sources, improving accuracy and traceability.
    • Define the number of background jobs that run concurrently to reduce system resource consumption, with a new Background Job Configuration tile available in the Vulnerability Manager Workspace Admin console under the Others section.

    See Vulnerability Response for more information.

    Important:
    Vulnerability Response is available in the ServiceNow Store. For details, see the "Activation information" section of these release notes.

    Important information for upgrading Vulnerability Response to Australia

    Starting with Australia Patch 5, Now Assist for Vulnerability Response is being prepared for future deprecation. It will be hidden and no longer installed on new instances but will continue to be supported. For details, see the Deprecation Process [KB0867184] article in the Now Support Knowledge Base.

    ServiceNow Otto® is the new AI experience brand. This change is reflected in the name of ServiceNow products, including the Now Assist for Vulnerability Response product name, which will be replaced with ServiceNow Otto for Unified Security Exposure Management. Your product entitlements remain unchanged. Check your entitlements to determine your access to specific features.

    If you're currently using Vulnerability Response, and you do not intend to upgrade to Unified Security Exposure Management (USEM), install a version below v30.x of Vulnerability Response and for upgrades to supported third-party integration applications.

    For more information about the released versions of the Vulnerability Response application as well as the third-party and ServiceNow applications that are compatible with the Australia release, see the Vulnerability Response Compatibility Matrix and Release Schema Changes [KB0856498] article in the Now Support Knowledge Base

    New in the Australia release

    Streamline Microsoft SCCM data ingestion with JDBC
    Connect to Microsoft SCCM using JDBC (Java Database Connectivity) to query the SCCM database directly for collection, device, patch update, and deployment status data. Opening a firewall port for WMI (Windows Management Instrumentation) RPCs (remote procedure calls) is no longer required for these queries. A WMI connection remains required to deploy patches, because patch deployment continues to use the Microsoft SCCM API over WMI.
    Enhancements to the Invicti Vulnerability Integration
    Added the Invicti Platform Integration. Support for the Invicti Platform APIs introduces three new integration jobs that connect directly to the Invicti Platform cloud service:
    • Application Integration — Imports the list of applications being scanned in Invicti Platform into your ServiceNow AI Platform® instance as discovered applications.
    • Scan Integration — Pulls scan records from Invicti Platform, providing scan metadata to correlate with vulnerability findings.
    • Vulnerability Integration — Imports application vulnerability findings from Invicti Platform and creates or updates application vulnerable items in Vulnerability Response in your ServiceNow AI Platform®.

    Enhancements to Application life-cycle management: When an application is deleted or decommissioned in Invicti Platform, your ServiceNow AI Platform® automatically deactivates the corresponding discovered application and closes all associated application vulnerable items (AVITs), keeping your vulnerability inventory accurate without manual cleanup.

    Activate the Wiz Asset Integration and identify resource types for import
    Enhancements to the Wiz integration include:
    • Starting with version 32.1 (USEM) and version 4.1 (non-USEM), the Asset integration is deactivated by default and is not a mandatory prerequisite for the other Wiz integration imports.

      If you choose to activate it, the Asset integration will retrieve assets for all resource types if you don't specify the ones you want on the Asset Integration Configuration tab. To avoid importing vulnerability data you don't need, identify only the resources (assets) that you want to import with this integration.

    • Resource Type is no longer a mandatory field for configuring the Vulnerability Response Integration with Wiz. You can now save Wiz configurations for the integrations without specifying a Resource Type, simplifying setup for use cases where specifying a Resource Type isn't appropriate.
    Unified Microsoft Defender Integration for Security Exposure Management
    The Microsoft Defender for Cloud and Microsoft Defender Threat and Vulnerability Management (MS TVM) plugins are now consolidated into a single plugin: Microsoft Defender Integration for Security Exposure Management. This consolidation deprecates the standalone Microsoft Defender for Cloud plugin. The unified plugin also introduces container image vulnerability ingestion from Microsoft Defender for Cloud, creating Container Vulnerable Items on your instance. A guided migration path is available to transfer existing data from the deprecated applications to the unified plugin.
    AWS Integration for Security Exposure Management
    The AWS Integration for Security Exposure Management supports integrations with the following AWS services:
    • AWS Inspector is an automated vulnerability management service that continuously scans EC2 instances, ECR container images, and Lambda functions for software vulnerabilities (CVEs) and unintended network exposure. The Vulnerability Response integration with AWS Inspector imports host and container vulnerability findings from AWS Inspector.
    • AWS Security Hub is a security service that is used to centralize and update security checks across AWS accounts. It provides a unified view of security alerts and compliance status by integrating with various AWS services. The Vulnerability Response integration with AWS Security Hub imports host, container vulnerabilities, and misconfigurations from AWS Security Hub.
    Enhancement to Vulnerability Response CI lookup rule configuration
    The Applies to field is added to Configuration (CI) lookup rule records. For third-party and ServiceNow® integrations that support both Application Vulnerability Response (AVR) and Vulnerability Response (VR) lookup rules, like the Vulnerability Response Integration with Wiz, for example, select one for a rule:
    • Discovered Application for Application Vulnerability Response lookup rules.
    • Discovered Item for Vulnerability Response lookup rules.
    Note:
    The field is left empty by default. If you leave this field empty for lookup rules that support both VR and AVR integrations, background jobs for both applications apply changes on the same set of lookup rules. This state might cause a conflict and set the reapply flag incorrectly. With this distinction set, after the respective background jobs for AVR and VR are completed, the system resets the flag only for the lookup rules for the background job that was run.
    Optimized Tenable.io Compliance Results ingestion
    Starting with v 6.1.3, the Tenable.io Compliance Results Integration is replaced by the Tenable.io Fixed Compliance Results Integration and Tenable.io Open Compliance Results Integration. Compliance results are now imported based on their status, optimizing ingestion performance and scalability for environments with large volumes of compliance data while keeping remediation and compliance tracking aligned with the current state of findings.
    Qualys Integration – API enhancements
    The Qualys Vulnerability Integration has been upgraded to support newer Qualys API versions across Host Detection, Host List, Knowledgebase, PC Controls, PC Policies, and PCRS integrations. The integrations now ingest additional data fields, including vulnerability detection source, authentication privilege status, active status for controls and policies, and cloud metadata, giving you better visibility into your vulnerability and compliance data. Use the new posture_api_version integration instance parameter to choose between the default v2.0 APIs or the newer v5.0 streaming APIs for the PCRS Policy Host and PCRS Test Results integrations.
    Vulnerability Data Management with Central Vulnerability Database (CVDB)
    The Central Vulnerability Database (CVDB) introduces a unified, source-agnostic vulnerability data layer that consolidates data from multiple sources into a single authoritative record, improving accuracy, consistency, and traceability. Key capabilities include:
    • Unified vulnerability record: Correlates vulnerability data from multiple sources, supports sources including National Vulnerability Database (NVD), scanner intelligence, European Union Vulnerability Database, Japanese Vulnerability Database, and vulnerability intelligence feeds.
    • Priority-based data reconciliation configuration:
      • Field-level priority: Ensures each attribute (e.g., CVSS, remediation, exploit status) can be configured from the most reliable provider.
      • Source-level priority: Applies a global ranking when field-level rules are not defined.
      • Hybrid model: Field-level rules take precedence, with source-level fallback; all source data is preserved for full traceability.
    • Source attribution and traceability: Maintains detailed source metadata, timestamps, and change history to ensure full auditability and transparency.
    • Data enrichment: Combines CVSS scores, exploit intelligence, and remediation guidance to provide a richer and more actionable vulnerability context.

    Changed in this release

    Vulnerability Response assignment rules
    The sn_vul.rerun_task_rules system property for rerunning assignment rules was changed to sn_sec_rem.rerun_task_rules. Users must activate this property (set to 'true') to rerun assignment rules.
    Improved vulnerability assessment workflows
    • CI filtering for vulnerability assessments: You can now filter which configuration items are included in a vulnerability assessment using a condition builder.
    • Business Application population on AVITs: AVITs created from SBOM assessment results now include Business Application information, helping you understand application impact and prioritize remediation.
    • Priority roll‑down from vulnerability assessments: Updates to the priority of a vulnerability assessment now automatically roll down to associated VITs and AVITs, ensuring consistent prioritization based on the highest severity.
    Remediation task rule execution mode
    You can now choose how remediation task rules are evaluated during ingestion. The new Match First execution mode evaluates rules sequentially and applies only the first matching rule, assigning each finding to exactly one remediation task. The default Match All mode continues to evaluate all applicable rules.
    Enhanced Compensatory controls
    When new vulnerable items are ingested and associated with a remediation task that already has an approved compensating control, the reduced risk rating is now automatically inherited by those new vulnerable items.

    Activation information

    Install Vulnerability Response and supported third-party integrations by requesting them from the ServiceNow Store. Visit the ServiceNow Store to view all the available apps, and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.