---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Ungrouped Vulnerability Response vulnerable items

# Ungrouped Vulnerability Response vulnerable items {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Vulnerable items are automatically assigned to a remediation task when they are
imported. However, sometimes, if a vulnerable item (VI) is created manually, for example, the VI
can become an orphan. The Ungrouped vulnerable item module lists those
vulnerable items without a group.  
Note:  
Integration automated processes do not create orphans, so this use case is expected to be small.

Being ungrouped occurs if a vulnerable item was created without a vulnerability, or there is
no remediation task rule that assigns the VI to a group.

In that case, review the list of ungrouped vulnerable items by navigating to AllVulnerability ResponseVulnerable itemsUngrouped.  
After review, your choices are as follows:

* You can [Create or edit Vulnerability Response remediation task rules](https://servicenow-prod.fluidtopics.net/gjnIR~u_kUymvXKMt0Lqng "After you complete your initial assessment of remediation task rules using Setup Assistant, you can create rules to automatically group vulnerable items based on filter conditions. These rules automatically group vulnerable items as they are imported or manually created. Use the filter to limit the vulnerable items grouped by this rule, such as selecting all vulnerable items with exploits.") to catch any items that appear on this list.
* You can [Manually create a remediation task in Vulnerability Response](https://servicenow-prod.fluidtopics.net/16Wxl5x6BP0pmlzjI_o~CA "Creating a remediation task manually is done when you want to group vulnerable items by something other than the Remediation Task Rules criteria. For example, you can create tasks for a particular manager, or for active, new exploits, such as ransomware that include different vulnerabilities. You can also use it to group ungrouped vulnerable items.") and manually add items from this list to the group or define a condition that matches these items.
* You can open an existing remediation task and [add any relevant
  vulnerable items to the group](https://servicenow-prod.fluidtopics.net/f32NhGwSbg0aCSK3QBfG8g "If a vulnerable item is left ungrouped, you can add it to a remediation task.") as long as it is in the Open or Under Investigation state.

{#ungrouped-vul-items__ul_krd_bjq_2db}  
Note:  
Manually added vulnerable items are not automatically removed from remediation tasks by remediation task rules or group conditions.

For more information on how remediation tasks and task rules behave, see [Vulnerability Response remediation tasks and remediation task rules overview](https://servicenow-prod.fluidtopics.net/a7Z9DVk5024DYfVdfELq8A "Configure remediation tasks (VULs) to help analysts and remediation specialists organize vulnerable items (VI) and analyze them in bulk. The criteria by which remediation tasks are formed is configured so that you do not have to manually assign vulnerable items into remediation tasks. Using remediation tasks, you can monitor progress and drive the remediation process more efficiently.").

*[\>]: and then


