Exception Management for Unified Security Exposure Management release notes

  • Release version: Store
  • Updated August 6, 2026
  • 5 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Exception Management for Unified Security Exposure Management release notes

    Exception Management for Unified Security Exposure Management (USEM) is a ServiceNow application designed to help organizations efficiently manage vulnerability exceptions. It streamlines the process for requesting, reviewing, and approving exceptions related to vulnerable findings, enhancing transparency, compliance, and audit readiness. The application automates workflows and captures justifications for exceptions, thereby reducing operational overhead while maintaining visibility into risk.

    Show full answer Show less

    Key Features

    • Bulk Edit and Approval: Support for bulk editing and bulk approve/reject actions on risk modification and exception requests enables users and approvers to handle multiple vulnerable items or exception requests simultaneously, improving efficiency in high-volume environments.
    • Smart Assessment Integration: Smart Assessment support is integrated into Risk Reduction options and exception workflows, allowing for enhanced risk evaluation and controlled assessment template upgrades with versioning support.
    • Improved Exception Workflow Controls: Enhancements include compensating controls workflow allowing risk rating increases, automatic cancellation or reopening of remediation tasks based on exception status changes, and refined GRC exception flows to ensure consistent item state management.
    • Security and Access Controls: Updated access controls ensure that the Request Exception action is properly displayed only to authorized users, and security vulnerabilities related to questionnaire design access have been fixed to restrict unauthorized usage.
    • Exception Rule Management: Exception rule configurations can now be included in update sets, supporting better change management across environments. Custom exception rule scripts are now compatible with platform scoped-script restrictions.
    • UI and Usability Enhancements: The application features updated form configurations for easier maintenance, improved approval UI with clickable summary cards, and removal of confusing UI buttons to prevent unintended actions.
    • Performance and Stability Improvements: Fixes include resolving memory issues with scheduled jobs, improving record update performance, and addressing workflow issues in remediation task deferrals across related vulnerability response applications.

    Practical Benefits for ServiceNow Customers

    • Automated and controlled exception management reduces manual effort and operational bottlenecks in vulnerability handling.
    • Enhanced bulk processing capabilities save time for security teams managing large volumes of exception requests.
    • Improved risk assessment workflows with Smart Assessments allow more accurate and flexible risk rating adjustments.
    • Better security controls and compliance through transparent exception documentation and controlled access.
    • Simplified upgrade and maintenance processes with improved form configurations and support for change management best practices.
    • Increased system stability and performance ensure reliable exception processing and reporting.

    Important Upgrade Note

    Version 30.2.1 introduces the USEM architecture, a significant upgrade from previous Vulnerability Response applications. Customers upgrading to USEM must use the provided Migration Assistant to ensure a safe transition. Customers not upgrading to USEM should select versions prior to 30.x for installation or upgrade.

    Version history for the ServiceNow® Exception Management for Unified Security Exposure Management application on the ServiceNow Store.

    Important:
    For details on system requirements and family compatibility, view the application listing on the ServiceNow Store website.
    Version 30.6.6 - August 2026 (USEM)
    • Fixed:
      • Expired False Positives or Exceptions reopen the original remediation task as expected instead of creating a duplicate remediation task.
      • Canceling a policy exception reverts the associated vulnerable item back to its original state as expected.
      • Fixed issues in the GRC exception flow so manually reopening a vulnerable item automatically cancels the related policy exception, and canceling an approved exception returns the item to an open state as expected.
      • False Positive requests are no longer automatically rejected and the Reopen action works for users configured with a non-English language.
      • Enhancements to the compensating controls (Mitigating Control in Place) workflow allows the risk rating to be increased, not just reduced.
      • Custom exception rule scripts configured in feature settings no longer fail due to a platform scoped-script evaluation restriction.
    Version 30.6.1 - July 2026 (USEM)
    • New:
      • Added bulk edit support for Risk modification requests, enabling users to evaluate and process multiple vulnerable items at once.
      • Added Smart Assessment support to the Risk Reduction option in Request Exception workflows.
    • Changed:
      • Updated security exception form configuration, simplifying maintenance and enabling faster future updates.
      • Updated access controls to correctly display the Request Exception action for authorized users.
      • Enhanced application to align with security directives.
    • Fixed:
      • Fixed an issue where exception request types in multi-language environments caused incorrect behavior in False Positive auto-rejection and Deferred item reopen actions.
      • Fixed a layout overlap on the Approvals page at narrow viewport widths.
      • Fixed remediation task deferral extension workflow issues in Application Vulnerability Response and Container Vulnerability Response.
    Version 30.5.0 - June 2026 (USEM)
    • New: Bulk edit now supports Risk Reduction, letting users evaluate and process risk reduction requests across multiple vulnerable items at once. - The Risk Reduction option via the Request Exception option now supports Smart Assessment.
    • Changed:
      • Migrated security exception form read-only configuration to the standard product codebase, improving maintainability and simplifying future updates.
      • Updated access controls so the Request Exception action is correctly displayed for authorized users.
    • Fixed: Application Vulnerability Response and Container Vulnerability Response remediation task deferral-extension workflow issues.
    Version 30.4.1 - June 2026
    • New: Added Smart Assessment versioning support for Exception templates to enable safer and more controlled template upgrades on customer instances.
    • Changed:
      • Migrated security exception form read-only configuration to the standard product codebase, improving maintainability and simplifying future updates.
      • Updated access controls so the Request Exception action is correctly displayed for authorized users.
      • Enhancements to support template-related record updates. You might see improved performance for record updating.
    • Fixed:
      • Application Vulnerability Response and Container Vulnerability Response remediation task deferral-extension workflow issues.
      • Issues that were identified during unit-test coverage improvements.
    Version 30.3.4 - May 2026
    • Fixed:
      • An issue where conditional questionnaires failed to trigger on exception submission after upgrading to Unified Security Exposure Management (USEM), affecting both pre-upgrade and newly created questionnaire configurations.
      • The out-of-memory error and platform node restart caused by the scheduled job responsible for refreshing Change Approval fields. The job now completes successfully within memory limits.
      • An issue where cancellation and deletion operations on exception rules did not execute as expected.
    Version 30.3.2 - April 2026
    • Fixed:
      • An issue where vulnerable items were not transitioning to a closed state after their associated detections were closed, because the exception rule scheduled job was not checking for the closed state on finding records.
      • A performance degradation in USEM ingestion caused by redundant repeated queries to the findings configuration table during exception processing. A static method has been implemented for invocation that eliminates the unnecessary per-instance overhead.
      • The bulk approve and reject modal incorrectly opening for non-eligible records, preventing approvers from inadvertently acting on records that do not qualify for bulk processing. List view layout enhancements might improve usability.
      • Resolved VIT records incorrectly remaining in a "Deferred" state after an Exception Rule was deleted, caused by deferral fields not being cleared properly during final state transitions.
      • Fixed a security vulnerability where the "Design new questionnaire" UI action could be accessed by unauthorized users due to an ACL bypass, ensuring only permitted users can access questionnaire design functionality.
      • Resolved multiple exception management issues in the Risk Reduction and Questionnaire approval flows, including incorrect state transitions and edge cases in approval handling.
    • Changed:
      • Introduced Bulk Approve and Reject capability for approvers, enabling them to process multiple exception requests simultaneously from a single list view, which can help with significantly reducing manual effort for high-volume approval workflows.
      • Added new KPI tiles to the Exception Management dashboard for Expiring Exceptions, Exception Extensions, and Repeated Rejections, giving approvers and managers additional visibility into exception health and lifecycle trends.
      • Exception Rule configurations can now be added to update sets, allowing administrators to capture and promote exception rule changes across environments as part of standard change management processes.
      • Improved the Approval UI with clickable summary cards, providing a more intuitive navigation experience for approvers reviewing and actioning exception requests.
      • Added support for category_roles in Smart Assessments and enabled quick editing of assessment templates, improving configurability of assessment-driven exception workflows.
      • Removed unnecessary UI action buttons (Resolve and Close) from the new AVIT creation form, preventing user confusion and unintended actions on records that have not yet been fully saved.
    Version 30.2.1 - January 2026
    • Note:
      This app version is intended for Unified Security Exposure Management (USEM), a significant architectural upgrade to the Vulnerability Response applications. If you are currently using Vulnerability Response and upgrading to USEM for the first time, you must use the Migration assistant for Unified Security Exposure Management to ensure a safe and successful upgrade. If you do not intend to upgrade to USEM, please select a version below 30.x when installing or upgrading.
    • Exception Management enables organizations to efficiently handle and document vulnerability exceptions. It provides a controlled process for requesting, reviewing, and approving exceptions to vulnerable findings, ensuring transparency and compliance. By automating workflows and capturing exception justifications, it helps reduce operational bottlenecks while maintaining risk visibility and audit readiness.