---
sourceDocument: Store Version History Release Notes
sourceDocumentLink: https://www.servicenow.com/docs/r/store-release-notes

 Release :

    - store

ft:locale :

    - en-US

ft:publication_title :

    - Store Version History Release Notes

ft:clusterId :

    - rnst

bundleId :

    - rnst


---

# Vulnerability Response Integration with NVD release notes

# Vulnerability Response Integration with NVD release notes {#ariaid-title1}

Release version: Store  
Updated October 8, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Vulnerability Response Integration with NVD release notes

The Vulnerability Response Integration with the National Vulnerability Database (NVD) enables ServiceNow customers to import, process, and analyze vulnerability data, including Common Vulnerability Scoring System (CVSS) scores, Common Platform Enumeration (CPE) data, and Stakeholder Specific Vulnerability Categorization (SSVC) attributes.
This integration supports automated risk scoring, vulnerability assessments, and improved data accuracy to strengthen vulnerability management workflows.
Show full answer Show less  

## Key Features

* **Automated Data Ingestion:** Integrates CVEs and CPEs from the NVD using updated APIs, including support for NVD API 2.0 and API keys for secure access.
* **SSVC Attributes:** Ingests and displays SSVC decision attributes such as Exploitation, Automatable, and Technical Impact, providing enhanced vulnerability context and enabling automatic risk score recalculations.
* **Improved Performance and Reliability:** Implements heartbeat signals during data processing to prevent timeouts, especially for high-volume CVE matches, ensuring robust and reliable integration operations.
* **Enhanced Access Control and UI:** Standardizes query access controls and updates the admin console UI for consistent and secure management.
* **Version Range Assessments:** Allows creation of vulnerability assessments without explicit CPE creation by leveraging NVD-provided version range information.
* **CVSS Score Handling:** Supports CVSS version 4.0 scores, fallback to CVSS 3.0 when 3.1 is unavailable, and uses secondary scores if primary scores are missing, ensuring accurate vulnerability scoring.

## Key Outcomes

* ServiceNow customers can seamlessly integrate the latest NVD vulnerability data into their vulnerability response processes to maintain up-to-date security posture information.
* Automated aggregation of SSVC attributes to vulnerability entities improves prioritization and decision-making for remediation efforts.
* Robust processing of large datasets without timeouts ensures continuous and reliable data synchronization.
* Enhanced data accuracy and control via source tagging ('NVD') and refined deletion rules prevent unintended data loss.
* Support for API key usage and updated API endpoints aligns the integration with current NVD standards, improving security and functionality.
* Ongoing maintenance and fixes ensure compatibility with evolving NVD data structures and scoring methodologies.  
Version history for the Vulnerability Response Integration with NVD on the ServiceNow Store.
Important:  
For details on system requirements and family compatibility, view the application listing on the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) website.

## Version history

Version 30.7.2 - October 2026
:   Fixed: When processing software with very high volumes of matched CVEs (for example, widely used applications), NVD CPE integration could time out and fail to complete, instead of failing silently with an invalid response error.

Version 30.7.0 - September 2026
:
    * New: SSVC decision attributes are now rolled up to corresponding TPEs. The system now aggregates Exploitation, Automatable, and Technical Impact values from CVE records to TPEs, and triggers automatic risk score recalculation when these attributes change.
    * Fixed: The NVD integration processor now sends periodic heartbeats to import queue entries, preventing timeouts during processing of large NVD data windows. Queue entries are no longer force-terminated while active processing is underway.

Version 30.4.2 - August 2026
:   New: NVD integration now ingests and displays SSVC assessment data for CVEs. The system now parses and stores Exploitation, Automatable, and Technical Impact attributes from the NVD CVE feed and API, making these SSVC decision
    points available on CVE records for analysis and reporting.

Version 30.3.1 - June 2026
:
    * Changed:
      * Admin console UI changes.
      * Migrated query access control definitions in National Vulnerability Database (NVD) to the standard product codebase, ensuring consistent access control enforcement.
      {#store-secops-rn-vr-nvd__ul_cck_rvf_kjc}

Version 30.3.0 - April 2026 (USEM)
:
    * Fixed: The Common Vulnerability Scoring System (CVSS) V4 score mapping to align with the latest NVD API response structure.
    * Changed: Added the no_audit_delete attribute to the NVD CPE key \[sn_vul_nvd_cpe_key\] table.
    {#store-secops-rn-vr-nvd__ul_kj4_3ls_t3c}

Version 1.7.4 - April 2026
:
    * Fixed: The Common Vulnerability Scoring System (CVSS) V4 score mapping to align with the latest NVD API response structure.
    * Changed: Added the no_audit_delete attribute to the NVD CPE key \[sn_vul_nvd_cpe_key\] table.

Version 1.7.1 - August 2025
:   New: Create assessments without explicitly creating CPEs using the Version Range information that the National Vulnerability Database (NVD) provides.

Version 1.6.1 - May 2025
:   Changed: The 'Source' column in the reference table and the CPE field should be populated with 'NVD'. If any changes occur, only the CPE and references marked with the source 'NVD' should
    be deleted.{#store-secops-rn-vr-nvd__latest-store-secops-rn-vr-nvd}
{#store-secops-rn-vr-nvd__latest-store-secops-rn-vr-nvd}

Version 1.5.3 - December 2024
:   Minor fixes for this release.

Version 1.5.1 - November 2024
:   New: The National Vulnerability Database (NVD) now includes entries for the Common Vulnerability Scoring System (CVSS) score 4.0 values.

Version 1.4.5 - May 2024
:   Fixed: The NVD integration has been fixed to utilize the secondary CVSS score when primary CVSS score is unavailable.

Version 1.4.3 - February 2024
:   Changed: CVSS3.0 will be considered for processing if CVSS3.1 is not present in the NVD response.

Version 1.4.2 - November 2023
:   Fixed: Updated unmapped integration to use the cpesearch Rest Endpoint API so that the number of API calls are reduced to NVD for associating software with NVD entry if the NVD entry exists.

Version 1.3.3 - August 2023 (Vancouver)
:
    * New:
      * Created the following integrations to use NVD API 2.0 version.
      * NIST National Vulnerability Database Integration - API (CPE only). This integration fetches CPEs.
      * NIST National Vulnerability Database Integration - API (Unmapped CPE). This integration maps CPEs with the CVEs.
      {#store-secops-rn-vr-nvd__ul_dsr_3mx_hyb}
    * Changed: Deprecated existing integration i.e NIST National Vulnerability Database Integration - API (CVE and CPE).
    {#store-secops-rn-vr-nvd__ul_e1y_hmx_hyb}

Version 1.2.0 - May 2022
:   New: Added support for using API keys for calling NVD endpoints.

Version 1.1.0 - October 2021
:
    * Changed:
      * Modifications to support changes to the CPE APIs done by NIST. These changes restrict CPE APIs by limiting date ranges to 120 days.
      * When you enter a start or end date for the optional parameters, you need to provide both the start and end dates.

Version 1.0.3 - June 2021
:   Fixed: The "source" attribute is populated in the Third-party entry table for NVD records. Vulnerable Software records from NVD are available as expected.

Version 1.0.0 - February 2021
:
    * New:
      * Initial release.
      * Two NVD integrations that import the CVEs and CPEs information from the NIST National Vulnerability Database (NVD).
      {#store-secops-rn-vr-nvd__ul_zxq_vbq_wpb}
    {#store-secops-rn-vr-nvd__ul_yxq_vbq_wpb}

