---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure and run a scheduled job to update CVE records with EPSS data

# Configure and run a scheduled job to update CVE records with EPSS data {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Customize the base system scheduled job to update CVE records with EPSS data.

## Before you begin

Important:  
You need to download and activate the Vulnerability Response Integration with CISA (com.snc.vulnerability.cisa) plugin to enable the EPSS integration.
Following are the list of new fields added in NVD table to store EPSS data.

* EPSS Score
* EPSS Percentile
* EPSS Last Modified

{#config-schedule-job-update-cve-record-epss-data__ul_ldc_q5q_fyb}  
Note:  
Configure the list view or form view as per the requirement to view newly added fields.Role required: admin

## About this task

Data imports from the EPSS integration, further enriches the NVD data in your instance. If NVD records are not present, then it will create a placeholder in the CVE table and add EPSS details in the same table. Run this integration as part of your initial setup of Vulnerability Response and post to importing vulnerability data into your instance.  
Note:  
By default, the First.org EPSS Integration is in Active state. The base system scheduled job is configured, by default, to run daily.

## Procedure

1. Navigate to AllVulnerability ResponseAdministrationIntegrations.
2. Find and select First.org EPSS Integration.
3. Modify the fields, as needed.
4. Right-click on the header to Save your changes.
5. Select Execute Now, to run the scheduled job immediately.  
   You are returned to the Vulnerability Integrations view.
6. Select First.org EPSSVulnerability Integration Runs tab to view the progress of the import.  
   On successful completion of the scheduled job, the EPSS scores, percentile, and the last modified EPSS score timestamps are updated on the CVEs.

## What to do next

* See [Add EPSS Score condition in Risk calculator Business Rule](https://servicenow-prod.fluidtopics.net/SwAY2nDUsi3Y5~iQyeVreQ "Modify Business Rule to add EPSS score condition to Risk Calculator.").
* See [View Vulnerability Response vulnerability libraries](https://servicenow-prod.fluidtopics.net/JMOl4iNRK0~b7PHhzDFl1w "You can view vulnerability data imported from the National Vulnerability Database (NVD), Common Weakness Enumeration (CWE), or third-parties to decide whether to escalate a remediation task.") to see the imported entries.
{#config-schedule-job-update-cve-record-epss-data__ul_wdq_4xq_fyb}

*[\>]: and then


