---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create Vulnerability Response vulnerable items

# Create Vulnerability Response vulnerable items {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Multiple methods create vulnerable items (VI). Most commonly, an integration to a
vulnerability scanner is installed and configured to import results nightly. There are
cases, like physical security vulnerabilities, when you might prefer to manually add
vulnerable item records.

## Before you begin

Role required: sn_vul.vulnerability_write

## About this task

VIs that you create manually, and automatically-created VIs are automatically added
and removed from remediation tasks by remediation task rules and group
conditions.

## Procedure

1. Navigate to AllVulnerability ResponseVulnerable Items.
2. Select a category to open the list.
3. Click New.
4. Fill in the fields on the form, as appropriate.  
   For information on the vulnerable items fields see, [Vulnerability Response vulnerable item form fields](https://servicenow-prod.fluidtopics.net/3UUZMdj_UtcWxtNPHu8V2A "Vulnerable items are automatically created during third-party vulnerability integration imports.").
5. Right-click in the form header and click Save.  
   The remediation task rules evaluate the vulnerable item and add it to an
   existing task or creates a new task. If the evaluation fails, then the
   vulnerable item is added to Ungrouped Vulnerable Items list.  
   When you save a new vulnerable item, all the [enabled calculators](https://servicenow-prod.fluidtopics.net/3Hl03aogPFrru7chhJttaQ "Vulnerability calculators automate calculating initial values for the fields on vulnerable items. The condition for each calculator is evaluated in order, and the first matching calculator is used.") run.  
   Note:  
   Only one calculator per Target field is allowed to be active at a time. When you activate one, any others with the same Target field are deactivated.
6. You can click any of the related lists to view additional information.  
   You can use the Related Link, Scan for Vulnerabilities
   to manually trigger a ServiceNow® -initiated scan. For
   information on how to configure a vulnerability scanner, see [Configure and manage Qualys vulnerability scanners and scans](https://servicenow-prod.fluidtopics.net/LHibAKAl2TYK6hcWWVuBfw#c_VulnerabilityScans "Qualys vulnerability scans can be performed to find software vulnerabilities that affect your CIs. You can initiate scans from a vulnerable item record or by creating a scan record directly for configuration items (CIs) and IP addresses.").

   For a Qualys Vulnerability Integration, a default scanner is
   pre-installed in the Vulnerability Scanners module. This
   scanner is deactivated by default. Select the Active and
   Default check boxes to activate the Qualys scanner to
   work using the Scan for Vulnerabilities related link on the
   remediation task and vulnerable item forms.  
   The following editing and remediation options become available from the
   header bar:
   * Update: Saves updates to the form.
   * Create Security Incident: Creates a security incident.
   * Close: Closes the item. If all items in its group are closed, the remediation task automatically closes.
   * Request Exception: Submits a request to defer an item.
   * Resolve: Resolves the item.
   * Delete: Removes the vulnerable item.
   {#t_CreateVulnerableItems__ul_eyr_whc_v1b}
{#t_CreateVulnerableItems__steps_ldz_yl4_15}
**Related tasks**   

* [Edit vulnerable items in bulk in Vulnerability Response](https://servicenow-prod.fluidtopics.net/k4YNXsPtp1Z6nk4jFFUjxw "Edit vulnerable items in bulk to save time by selecting fields and running an asynchronous bulk edit job in the background.")

*[\>]: and then


