Application Vulnerability Response release notes

  • Release version: Australia
  • Updated July 31, 2026
  • 5 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Application Vulnerability Response release notes - Australia Release

    The ServiceNow Application Vulnerability Response (AVR) application enhances collaboration between security and IT teams to remediate critical application vulnerabilities more efficiently. The Australia release introduces significant improvements including new integrations, lifecycle management enhancements, and streamlined workflows that help customers better manage application vulnerabilities from discovery through remediation.

    Show full answer Show less

    Key Features

    • Wiz Application Vulnerability Response Integration: Import detailed vulnerability data including applications, Software Composition Analysis (SCA), and secrets (passwords, tokens, keys) directly from Wiz. This integration supports fine-grained asset type selection to avoid unnecessary data imports.
    • Invicti Platform Integration: New integration jobs for importing applications, scan metadata, and vulnerability findings from Invicti Platform cloud service, with automatic lifecycle management that deactivates applications and closes associated vulnerabilities when applications are deleted or decommissioned.
    • GitHub Secret Scanning Integration: Expanded support for importing generic secrets from GitHub repositories with configurable options to manage ingestion.
    • Vulnerability Data Management Enhancements:
      • Filtering Configuration Items (CIs) for vulnerability assessments using a condition builder.
      • Automatic inclusion of Business Application information on Application Vulnerable Items (AVITs) created from SBOM assessments to aid impact analysis and prioritization.
      • Priority roll‑down from vulnerability assessments to VITs and AVITs ensuring consistent severity-based prioritization.
    • Compensatory Controls Improvements: New vulnerable items linked to remediation tasks with approved compensatory controls automatically inherit the reduced risk rating.
    • Configuration Enhancements: Introduction of an "Applies to" field on Configuration Item lookup rules to prevent conflicts where integrations support both AVR and Vulnerability Response (VR), improving data accuracy and processing efficiency.
    • Penetration Test Workspace: Monitor penetration test requests, findings, and team progress within a dedicated workspace.
    • Vulnerability Manager Workspace: Easily reevaluate risk scores, assignments, remediation dates, exceptions, and tasks for specific application vulnerable items.

    Important Considerations for ServiceNow Customers

    • AVR is available for installation from the ServiceNow Store; customers must request the application there.
    • If not migrating to Unified Security Exposure Management (USEM), customers should install versions of AVR below v30.x for compatibility.
    • Starting with Australia Patch 5, Now Assist for Vulnerability Response is being deprecated and replaced by ServiceNow Otto for Unified Security Exposure Management, though existing entitlements remain unchanged.
    • For customers using third-party scanner integrations, compatibility and upgrade information is available via the Vulnerability Response Compatibility Matrix and related knowledge base articles.

    Benefits for ServiceNow Customers

    • Accelerate remediation of application vulnerabilities by integrating multiple vulnerability data sources seamlessly.
    • Maintain accurate and up-to-date vulnerability inventories through automated lifecycle management and data synchronization.
    • Improve prioritization and risk assessment with enhanced workflows that ensure consistent severity handling and business impact awareness.
    • Reduce manual effort and potential errors with improved configuration options and automatic inheritance of compensatory controls.
    • Gain comprehensive visibility into penetration testing activities and overall security posture within ServiceNow.

    The ServiceNow® Application Vulnerability Response application brings security and IT together to enable you to remediate your most critical vulnerabilities more quickly and efficiently. Application Vulnerability Response was enhanced and updated in the Australia release.

    Application Vulnerability Response highlights for the Australia release

    • Import application vulnerability response data that includes application, Software Composition Analysis (SCA) and secrets data with the Wiz Application Vulnerability Response Integration.
    • If you're currently using Application Vulnerability Response and you want to upgrade to Unified Security Exposure Management (USEM), see Unified Security Exposure Management (USEM) release notes for more information about USEM and the Unified Security Exposure Management migration.
    • Integrate with supported third-party scanners to import vulnerability data and use automated workflows to prioritize, remediate, and manage findings (application vulnerable items (AVITs)). Each application vulnerability represents a vulnerability entry in the Common Weakness Enumeration (CWE) or third-party libraries.
    • Monitor your penetration test requests and findings, as well as your team's overall progress in the Penetration Test Workspace.
    • Reevaluate the risk score, assignments, remediation target date, exceptions, and remediation task for a specific set of application vulnerable items in the Vulnerability Manager Workspace.
    • Compare application vulnerability-related data and determine if application vulnerabilities are found in an application.

    See Application Vulnerability Response for more information.

    Important:
    Application Vulnerability Response is available in the ServiceNow Store. For details, see the "Activation information" section of these release notes.

    Important information for upgrading Application Vulnerability Response to Australia

    • If you are currently using Application Vulnerability Response, and you do not intend to upgrade to Unified Security Exposure Management (USEM), install a version below v30.x of Application Vulnerability Response and for upgrades to supported third-party integration applications.
    • For information about the new features of Vulnerability Response, see the Vulnerability Response release notes.
    • For more information about the released versions of the Application Vulnerability Response application as well as the third-party and ServiceNow applications that are compatible with the Australia release, see the Vulnerability Response Compatibility Matrix and Release Schema Changes [KB0856498] article in the Now Support Knowledge Base.

    Starting with Australia Patch 5, Now Assist for Vulnerability Response is being prepared for future deprecation. It will be hidden and no longer installed on new instances but will continue to be supported. For details, see the Deprecation Process [KB0867184] article in the Now Support Knowledge Base.

    ServiceNow Otto® is the new AI experience brand. This change is reflected in the name of ServiceNow products, including the Now Assist for Vulnerability Response product name, which will be replaced with ServiceNow Otto for Unified Security Exposure Management. Your product entitlements remain unchanged. Check your entitlements to determine your access to specific features.

    New in the Australia release

    Enhancements to the Invicti Vulnerability Integration
    Added the Invicti Platform Integration. Support for the Invicti Platform APIs introduces three new integration jobs that connect directly to the Invicti Platform cloud service:
    • Application Integration — Imports the list of applications being scanned in Invicti Platform into your ServiceNow AI Platform® instance as discovered applications.
    • Scan Integration — Pulls scan records from Invicti Platform, providing scan metadata to correlate with vulnerability findings.
    • Vulnerability Integration — Imports application vulnerability findings from Invicti Platform and creates or updates application vulnerable items in Vulnerability Response in your ServiceNow AI Platform®.

    Enhancements to Application life-cycle management: When an application is deleted or decommissioned in Invicti Platform, your ServiceNow AI Platform® automatically deactivates the corresponding discovered application and closes all associated application vulnerable items (AVITs), keeping your vulnerability inventory accurate without manual cleanup.

    Configuring lookup rules
    The Applies to field is added to the Rules page for Configuration (CI) lookup rule records. For third-party and ServiceNow® integrations that support both Application Vulnerability Response (AVR) and Vulnerability Response (VR) lookup rules, like the Vulnerability Response Integration with Wiz, for example, select one for a rule:
    • Discovered Application for Application Vulnerability Response lookup rules.
    • Discovered Item for Vulnerability Response lookup rules.
    Note:
    The field is left empty by default. If you leave this field empty for lookup rules that support both VR and AVR integrations, background jobs for both applications apply changes on the same set of lookup rules. This state might cause a conflict and set the reapply flag incorrectly. With this distinction set, after the respective background jobs for AVR and VR are completed, the system resets the flag only for the lookup rules for the background job that was run.
    Activate the Wiz Asset Integration and identify resource types for import
    Enhancements to the Wiz integration include:
    • Starting with version 32.1 (USEM) and version 4.1 (non-USEM), the Asset integration is deactivated by default and is not a mandatory prerequisite for the other Wiz integration imports.

      If you choose to activate it, the Asset integration will retrieve assets for all resource types if you don't specify the ones you want on the Asset Integration Configuration tab. To avoid importing vulnerability data you don't need, identify only the resources (assets) that you want to import with this integration.

    • Resource Type is no longer a mandatory field for configuring the Vulnerability Response Integration with Wiz. You can now save Wiz configurations for the integrations without specifying a Resource Type, simplifying setup for use cases where specifying a Resource Type isn't appropriate.
    Wiz Application Vulnerability Response Integration
    Import application, Software Composition Analysis (SCA), findings, Secrets (passwords, tokens and keys) data with the following Wiz Vulnerability integrations:
    • Application List Integration
    • SCA Findings Integration
    • Secret Findings Integration

    You can configure these integrations on the Wiz Vulnerability Integration configuration page along with the other Wiz Vulnerability integrations. View imported application list data such as Product Model and Source application ID from Wiz on the Discovered Applications [sn_vul_app_release] table records, and SCA and Secrets data on the Application Vulnerable Items [sn_vul_app_vulnerable_item] table records.

    GitHub Application Vulnerability Integration – Generic secrets support
    The GitHub Secret Scanning Integration supports imports of generic secrets in addition to standard secrets from your GitHub repositories. An enhanced Manage generic secrets in ServiceNow configuration option lets you control whether generic secrets are ingested. Imported secrets are mapped to Application Vulnerable Items (AVITs) with the scan type, Secret, while generic secrets are mapped with the scan type, Generic Secret.
    Improved vulnerability assessment workflows
    • CI filtering for vulnerability assessments: You can now filter which configuration items are included in a vulnerability assessment using a condition builder.
    • Business Application population on AVITs: AVITs created from SBOM assessment results now include Business Application information, helping you understand application impact and prioritize remediation.
    • Priority roll‑down from vulnerability assessments: Updates to the priority of a vulnerability assessment now automatically roll down to associated VITs and AVITs, ensuring consistent prioritization based on the highest severity.
    Enhanced Compensatory controls
    When new vulnerable items are ingested and associated with a remediation task that already has an approved compensating control, the reduced risk rating is now automatically inherited by those new vulnerable items.

    Activation information

    Install Application Vulnerability Response by requesting it from the ServiceNow Store. Visit the ServiceNow Store to view all the available apps, and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.