---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Exposure assessment by publisher software

# Exposure assessment by publisher software {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Assess exposure for zero-day vulnerabilities, when Common Vulnerabilities and Exposures (CVEs) for the asset or configuration item is unavailable. It uses the software information to assess exposure, using the software
discovery model.  
For information on assessing exposure by software, see:

* [Add software by a publisher for exposure assessment](https://servicenow-prod.fluidtopics.net/ca_RM0T67JZKU4zGFsu~~w "Add software by a publisher to the Exposure Assessment module to assess the impact of a new vulnerability or zero-day vulnerability.")
* [Create VIs for software by a publisher for exposure assessment](https://servicenow-prod.fluidtopics.net/UHtiudqPRxM2POk1vSvt8g "Create vulnerable items (VIs) from the Exposure Assessment page to analyze the list of VIs and recommend solutions and patches that can help the IT team to patch the vulnerabilities.")
* [Activate or deactivate software by a publisher for exposure assessment](https://servicenow-prod.fluidtopics.net/kp4U3mRDwgdkaYqYNOccag "Activate or deactivate software by a publisher to stop delta processing of the software and remove it from the active list of software.")
* [Export impacted CIs for software by a publisher in the Vulnerability Assessment workspace](https://servicenow-prod.fluidtopics.net/lF4Ol_S5lSlOrsujJe1RvQ "You can track the impacted assets list for new software by exporting the configuration items (CIs) related to an exposure assessment record to an excel sheet. This sheet can be used to share the assets details and owners to create incidents with the known impacted assets for the zero-day vulnerabilities.")
{#vr-ws-exposure-publisher__ul_zd4_wwn_dyb}

