---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Patch data and state rollup for patch orchestration in Vulnerability Response

# Patch data and state rollup for patch orchestration in Vulnerability Response {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Patch data and state rollup for patch orchestration in Vulnerability Response

Starting with version 16.1 of Vulnerability Response, patch data and status are aggregated and displayed on Patch Update records within the Vulnerability Response application.
This integration connects patch information, vulnerability solutions, and vulnerabilities to enable effective patch orchestration directly from Vulnerability Response.
Show full answer Show less  
Patch Update records are accessible in both classic and workspace environments, providing detailed data on patches, vulnerable items, associated devices, and remediation progress. This capability supports managing and tracking patch deployments and approvals in a unified platform.

## Key Features

* **Patch Data Integration:** Patch and vulnerability solution data imported by the Vulnerability Solution Management application appear directly in Vulnerability Response records.
* **Remediation Status Tracking:** Displays the number of devices affected, devices missing updates, percentage of vulnerable items remediated, and total vulnerable items with preferred patches.
* **Related Links and Tabs:** Access associated devices, vulnerable items, patch deployments, and patch requests from Patch Update records in both classic and workspace views.
* **Patch Requests:** Allows remediation owners to submit patch deployment requests for approval, streamlining the orchestration workflow.
* **Role-Based Access:** Users require specific patch orchestration integration roles to view and schedule patches, supporting integrations such as HCL BigFix and Microsoft SCCM.
* **State Rollup and Automation:** Vulnerable items with preferred patches automatically transition to the "Awaiting Implementation" state under defined conditions, reflecting patch scheduling and remediation targets.
* **Dashboard and Scorecard Views:** Patch orchestration data is visible on Vulnerability Response dashboards and scorecards, providing insights into patch status and remediation progress.

## How It Works in Practice

When a vulnerability matches a Configuration Item (CI) in the CMDB, a vulnerable item (VI) record is created. If the associated CI is missing a patch from a third-party vendor, a preferred patch is identified and linked to the VI. This patch data rolls up to solutions, enabling remediation tracking.

Users can drill down into patch details by clicking the Preferred Patch information icon, which reveals:

* Vulnerable items linked to the patch
* Associated devices and their update status
* Scheduled deployments for the patch
* Submitted patch requests awaiting approval
* Potential patches that may address the vulnerability

## Practical Benefits for ServiceNow Customers

* Gain unified visibility of patch and vulnerability data to improve remediation efficiency.
* Automate vulnerable item state transitions based on patch scheduling and remediation deadlines.
* Manage patch deployment approvals and schedules in one place with role-based security.
* Leverage integrations with patch orchestration tools like HCL BigFix and Microsoft SCCM for streamlined workflows.
* Use dashboards and scorecards to monitor patch orchestration progress and compliance.

## Additional Notes

If no vulnerability solution data is available after import, the Vulnerability solution field on Patch Update records remains blank. Specific guidance for viewing such patches is provided separately.  
Starting with v16.1 of Vulnerability Response patch data and states are rolled up to
Patch Update and other records in the Vulnerability Response application.

## Patch Update records in the workspaces in the classic environment in Vulnerability Response {#vr-patch-rollup-data__section_ddb_whj_rsb}

Information about patches, vulnerability solutions, and vulnerabilities is all connected in
the Vulnerability Response application.

Patch data and patch rollup data and status are displayed on records in your instance. Patch
records are included as part of the patch orchestration feature of this integration with Vulnerability Response. View Patch (VPU) records in Vulnerability Response Workspaces from the
List view in the IT Remediation Workspace. Patch Update records in both the classic view and
Vulnerability Response Workspaces include the following data:

* Vulnerability solution data and information from patch vendors imported by the Vulnerability Solution Management application.
* Source Remediation Status that includes the total number of devices that have a vulnerability that can be fixed by a patch, and any devices that are missing updates.
* Remediation Status that includes % of VIs remediated, and the total VIs that have a patch as a preferred patch.
* Associated Devices, Vulnerable Items, Patch Deployments and Patch Requests on the Related Links on records in the class view. This data is displayed on tabs on records in the Vulnerability Response Workspaces.
* Patch Requests that remediation owners have submitted for approval.
{#vr-patch-rollup-data__ul_zc3_13j_rsb}

## Roles required {#vr-patch-rollup-data__section_orz_kby_rsb}

Users need roles that are specific to the patch orchestration integration you are using to
view data and schedule patches. See the supported integrations for more information.

* [Understanding the HCL BigFix patch orchestration integration with Vulnerability Response](https://servicenow-prod.fluidtopics.net/h73nSOqPqd59_wefnz5Itg "You can manage patches and patch deployments for critical vulnerabilities for large groups of assets with the Vulnerability Response patch orchestration integration with the HCL BigFix product.") and [Vulnerability Response patch orchestration integration with Microsoft SCCM](https://servicenow-prod.fluidtopics.net/PZV21C07W_aS_du2IqIsmA "The Vulnerability Response integration with the Microsoft System Center Configuration Manager (SCCM) supports patch management and deployment for critical vulnerabilities across your assets.").
* [Viewing patch orchestration data on the Vulnerability Response dashboards](https://servicenow-prod.fluidtopics.net/d2Kqa8fLzXACQcbCmeFjuQ "Starting with v16.1, you can view patch update data in the classic environment on the dashboards that are included with the Vulnerability Response application.") in the classic environment.
* View data on scorecards in the [Vulnerability Response Workspaces](https://servicenow-prod.fluidtopics.net/rnvJlmaJdvZZ6X1Xy~qocQ "Vulnerability Response Workspaces offer a consolidated view of the features that enables you to multi-task from within the same pane by boosting productivity and saving time.").
{#vr-patch-rollup-data__ul_czq_hvq_psb}

## Patch data and state rollup {#vr-patch-rollup-data__section_tsk_33j_rsb}

To view the vulnerable items that have patches and that are assigned to you in the classic environment,
navigate to AllVulnerability ResponseVulnerable itemsAssigned to me with patches.

If a vulnerable item record is populated with a preferred patch, it transitions automatically
to Awaiting Implementation only if the state of the VI is not
Closed, Resolved, Deferred
or In Review. To drill down into the data to view the preferred solution
and other data, click the Remediation tab on the VI record.
Figure 1. Remediation Steps tab  
A VI with a preferred patch transitions to Awaiting Implementation in the following cases:

* If a patch is scheduled for deployment on a CI that is part of a collection import, and the CI has an associated VI, the reason the VI is Awaiting Implementation is Patch Scheduled.
* If a patch is scheduled for deployment on a CI that is part of a collection import, and the CI has an associated VI, and the Remediation target date (deadline) that is later than the Time to Remediation (TTR) date, the state of the VI is Awaiting Implementation with the reason as Patch Scheduled (Missing Target Date).
* If a patch is not scheduled for deployment on a CI that is part of a collection import, the state of the VI is Awaiting Implementation, with the reason as Patch Not Scheduled.
{#vr-patch-rollup-data__ul_xlm_cjj_rsb}

Click the Preferred Patch information icon to open the Patch updates
and view the following information on the Related Links:

Vulnerable items
:   Vulnerable items that are associated with this patch.

Associated Devices
:   Devices that have updates and those that are missing updates.

Patch deployments
:   Deployments scheduled for this patch on individual machines (assets) or on groups of
    assets.

Patch Requests
:   A list of patch requests that have been sent for approval before they are scheduled for
    deployment.

Potential Patches
:   Patches that might address a vulnerability.

Click the Preferred patch information icon to open the record to view
the information listed previously, in addition to the following Patch Update data:

Source Remediation Status
:   The total devices that require this patch and any devices that are missing the patch.

Remediation Status
:   The status (total VIs, % remediated, VIs deferred) for the VIs that have this preferred
    patch.

## Preferred patches and solutions {#vr-patch-rollup-data__section_z3k_5nh_tsb}

When an imported vulnerability matches an asset in your Configuration Management Database (CMDB), a vulnerable item (VI) is created in Vulnerability Response. If the configuration item (CI) that is associated with this VI is also
imported from a third-party patch vendor and is shown as missing a patch for the same
vulnerability, a preferred patch is listed and rolled up to your solutions. This information
lets you know that an asset (CI) has a fix from an available patch that is the best match for
its vulnerability.

## Viewing patches without solutions {#vr-patch-rollup-data__section_zmq_bzg_tsb}

After an import, if no vulnerability solution data is available, the Vulnerability solution field on the Patch Update record is left blank. For more information about
how to view information for these types of patches, see [View patches without solutions in Vulnerability Response](https://servicenow-prod.fluidtopics.net/hr4XKhmE3zraJ1QgDndJfg "Starting with v16.0 of Vulnerability Response, for patches that have no solutions after an import, the system then searches for patch IDs in the vulnerability reference data so that you can view these patches on vulnerability records.").

*[\>]: and then


