---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Vulnerability Response remediation task and vulnerable item states

# Vulnerability Response remediation task and vulnerable item states {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

With the Vulnerability Response application, you can use the state model to see the status of a remediation task, at any given time. Knowing how each state relates to and affects each other helps you to determine when and how to remediate
your vulnerable items (VIs).

## Remediation task states {#vulnerabillity-states__VulnGrpStates}

Complex use cases can sometimes result in a vulnerable item being in a different state than its remediation task. Understanding how states work helps to explain this behavior and can help with creating remediation tasks and creating or editing remediation task rules.  
Note:  
Starting with v23.0 of Vulnerability Response, the Vulnerable Item State Approval workflow is deprecated and replaced by the flow Vulnerability State Approval Change in the flow designer.  
Remediation tasks have many possible states as shown in the following diagram. Figure 1. Vulnerability Response state flow  
Note:  
Each task form contains Follow and Update buttons that are standard for ServiceNow tasks.

For more information on remediation task states and actions you can perform on it at a respective state, see [Vulnerability Response remediation task states](https://servicenow-prod.fluidtopics.net/gfzl087_DD6DEMX2PTbn1g "Third-party integrations import vulnerable item detection data that create new vulnerability items (VITs) or update existing VITs. Detection states update VIT states in so far as they’re Open or Closed.").

For more information on detections, remediation task and vulnerable item states, see [Detections, remediation tasks, and vulnerable item states](https://servicenow-prod.fluidtopics.net/8UzWFlCLEh1yT6CUM6qR2g "Third-party integrations retrieve the vulnerable item detection data. Detections are distinct occurrences of vulnerabilities as reported by the scanners.").

For more information on remediation task and VI states, see [Remediation tasks and vulnerable item states](https://servicenow-prod.fluidtopics.net/nngJCL~cF3g9IbwvUlrXiw "Remediation tasks and vulnerable items states can affect each other. Most of the time, a remediation task state updates the vulnerable item state, with the highest precedence task state used to update the vulnerable items in the group.").

For more information on remediation task state for VIs in multiple groups, see [Remediation task state for Vulnerable Items (VITs) in multiple groups](https://servicenow-prod.fluidtopics.net/L2vK8s0D~HIkBuI6eGo1Aw "When a VIT is in multiple remediation tasks, (RT in the following tables), and its own state has not been set, the higher precedence group state determines the state of that VIT, as shown in the following table.").
* **[Vulnerable item age calculation and display](https://servicenow-prod.fluidtopics.net/FOvirKinBn6uoQntzDnWGQ)**   
  The age of vulnerable items (VIs) is displayed in the Vulnerability Response application with more detail.

