---
sourceDocument: Zurich Release Notes
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/zurich/release-notes

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Release Notes

ft:clusterId :

    - rn

bundleId :

    - rn


---

# Container Vulnerability Response release notes

# Container Vulnerability Response release notes {#ariaid-title1}

Release version: Zurich  
Updated March 5, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 5 minutes to read  
The ServiceNow®
Container Vulnerability Response application brings security and IT together to enable you to remediate your most critical vulnerabilities more quickly and efficiently. Container Vulnerability Response was enhanced and updated in the Zurich release.

## About Container Vulnerability Response {#secops-container-vuln-resp-rn__secops-container-vuln-resp-rn-highlights}

* If you are currently using Container Vulnerability Response and you want to upgrade to Unified Security Exposure Management (USEM), see [Unified Security Exposure Management release notes](https://servicenow-prod.fluidtopics.net/8QvmC6k5y6yza6_yssFA4g#secops-sem-rn "The ServiceNow Unified Security Exposure Management application enhances exposure management with role-based views, enabling faster decision-making, efficient task handling, and streamlined approvals. It centralizes workflows, improves visibility across exposures, and enforces governance through configurable rules. With consistent navigation and integrated configuration, USEM boosts productivity, collaboration, and control across security operations, delivering a unified experience for exposures across assets. Unified Security Exposure Management is a new application in the Zurich release.") for more information about USEM and the Unified Security Exposure Management migration.
* Import container image vulnerability data from the Wiz scanners into container vulnerable items (CVITs) with the Vulnerability Response Integration with Wiz.
* With the sn_vul_container.vulnerability_analyst or sn_vul_container.vulnerability_admin role, create container remediation tasks manually in the Vulnerability Manager Workspace.
* With the role sn_vul_container.remediation_owner, create container remediation tasks manually in the IT Remediation Workspace.
{#secops-container-vuln-resp-rn__ul_odl_grr_w2c}

See [Container Vulnerability Response](https://www.servicenow.com/docs/access?context=cvr-landing&version=zurich&pubname=zurich-security-management&ft:locale=en-US) for more information.{#secops-container-vuln-resp-rn__secops-container-vuln-resp-rn-highlights-2}

## Activation and other requirements

Important:  
Container Vulnerability Response is available in the ServiceNow Store. For details, see the "Activation information" section of these release notes.

Activation information

:   Install Container Vulnerability Response and third-party integrations by requesting them from the ServiceNow Store. Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).{#secops-container-vuln-resp-rn__secops-container-vuln-resp-rn-activation-1}

Upgrade information

:   If you are currently using Container Vulnerability Response, and you do not intend to upgrade to Unified Security Exposure Management (USEM), install a version below v30.x of Container Vulnerability Response and for upgrades to supported third-party integration applications.{#secops-container-vuln-resp-rn__secops-container-vuln-resp-rn-upgrade-info-1}

    The Missing Assets \[sn_vul_wiz_missing_asset\] table used for storing assets imported by the backfill integrations for the [Vulnerability Response Integration with Wiz](https://www.servicenow.com/docs/access?context=vr-wiz-exploring-host-cf&version=zurich&pubname=zurich-security-management&ft:locale=en-US) is deprecated. If you are currently using the Vulnerability Response with Wiz integrations, after updating to version 1.1, you must backdate any of your existing Wiz primary integrations by three days and run them. Please review more information about the Wiz integration at [SecOps articles on the Security Operations Community](https://www.servicenow.com/community/secops-articles/announcement-wiz-integration-with-servicenow-secops/ta-p/3325055).{#secops-container-vuln-resp-rn__secops-container-vuln-resp-rn-upgrade-info-2}

    For more information about the released versions of the Container Vulnerability Response application as well as the third-party and ServiceNow applications that are compatible with the Zurich release, see the [Vulnerability Response Compatibility Matrix and Release Schema Changes \[KB0856498\]](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB0856498) article in the Now Support
    Knowledge Base.{#secops-container-vuln-resp-rn__secops-container-vuln-resp-rn-upgrade-info-3}

## Accessibility and localization

Accessibility information
:

    Dark theme
    :   The new Coral theme includes a dark theme option for web and mobile experiences. This option is commonly used to alleviate eye strain and improve readability.

## April 2026 {#ariaid-title2}

The ServiceNow®
Container Vulnerability Response application brings security and IT together to enable you to remediate your most critical vulnerabilities more quickly and efficiently. Container Vulnerability Response was enhanced and updated in the Zurich release.

### What's new {#secops-container-vuln-resp-rn-2026-04__secops-container-vuln-resp-rn-new-features}

[Remediation task rule execution mode](https://www.servicenow.com/docs/access?context=sem-grouping-multiple-findings-remediation-tasks-processing&version=zurich&pubname=zurich-security-management&ft:locale=en-US)
:   You can now choose how remediation task rules are evaluated during ingestion. The new Match First execution mode evaluates rules sequentially and applies only the first matching rule, assigning each finding to exactly one
    remediation task. The default Match All mode continues to evaluate all applicable rules.
{#secops-container-vuln-resp-rn-2026-04__secops-container-vuln-resp-rn-new-features-1}

## January 2026 {#ariaid-title3}

The ServiceNow®
Container Vulnerability Response application brings security and IT together to enable you to remediate your most critical vulnerabilities more quickly and efficiently. Container Vulnerability Response was enhanced and updated in the Zurich release.

### What's new {#secops-container-vuln-resp-rn-2026-01__secops-container-vuln-resp-rn-new-features}

[Enhancements to the Vulnerability Response Integration with Wiz](https://www.servicenow.com/docs/access?context=vr-wiz-exploring-host-cf&version=zurich&pubname=zurich-security-management&ft:locale=en-US)
:
    * The Universally Unique Identifier (UUID) that identifies detections for the Wiz Host Vulnerability integration will be mapped to a detection key.  
      Note:  
      This enhancement is supported for new customers only.

      For existing
      customers, the detection key for the Wiz Host Vulnerability integration is created using the combination of vulnerability, asset_id, and proof.
    * Added the source_id column to the Container Image Finding table (sn_vul_container_image_findings) and mapped the id attribute from the Wiz import to this field on findings records.  
      Note:  
      Perform a full import after upgrading to view the enhancement on container image findings, container image, and container image vulnerabilities records.
    * The image repository name format for new and existing discovered container images has been updated to align with the discovery format. The supported format is registry/repository. A separate finding is created for a repository present in each registry.
    * Appended all repositories that are associated with an image to the Repository field on the Discovered Container Image \[sn_vul_container_image\] table, which can help you see images from specific repositories.
    * The default integration instance parameter for configuring finding keys for the Container Vulnerability Integration includes src_ci, vulnerability, package, image_layer, and image_repository.
    {#secops-container-vuln-resp-rn-2026-01__ul_tmy_fmj_xhc}
{#secops-container-vuln-resp-rn-2026-01__secops-container-vuln-resp-rn-new-features-1}

## December 2025 {#ariaid-title4}

The ServiceNow®
Container Vulnerability Response application brings security and IT together to enable you to remediate your most critical vulnerabilities more quickly and efficiently. Container Vulnerability Response was enhanced and updated in the Zurich release.

### What's new {#secops-container-vuln-resp-rn-2025-12__secops-container-vuln-resp-rn-new-features}

[Enhancements to the Vulnerability Response Integration with Wiz](https://www.servicenow.com/docs/access?context=vr-wiz-exploring-host-cf&version=zurich&pubname=zurich-security-management&ft:locale=en-US)

:   The Missing Assets \[sn_vul_wiz_missing_asset\] is deprecated. After updating to version 1.1, you must backdate your existing primary Wiz integrations by three days and run them.

    The backfill integrations are activated by default.  
    After you run them after updating to v1.1, the following backfill integrations are no longer required:

    * Host Vulnerability Backfill Integration
    * Test Results Backfill Integration
    * Host Test Results Backfill Integration
    * Issues Backfill Integration
    {#secops-container-vuln-resp-rn-2025-12__ul_a2c_chb_nhc}

    Data for resources that have the validated_at_runtime flag set to 'yes' is imported and populated on detections.

    The CMDB internet-facing field on the discovered item is mapped to Limited Internet Exposure on findings.

    Fix information that includes 'Fix available', 'Partial fix available', 'No fix available', and 'Fix version' from the \[fix_available\] and \[fix_version\] columns is rolled up to CVITs from findings. Note: If there are two or
    more findings on a CVIT, the fixed version might only apply to one. In that case, 'Partial fix available' is rolled up to the CVIT.

    The Wiz vendor severity attribute is mapped to the 'Source severity' column on findings records in the Container Image Findings \[sn_vul_container_image_findings\] table.

    The cluster and namespace is evaluated for all the following entity Types: DEPLOYMENT, DAEMON_SET, STATEFUL_SET, POD.
{#secops-container-vuln-resp-rn-2025-12__secops-container-vuln-resp-rn-new-features-1}

## Zurich {#ariaid-title5}

The ServiceNow®
Container Vulnerability Response application brings security and IT together to enable you to remediate your most critical vulnerabilities more quickly and efficiently. Container Vulnerability Response was enhanced and updated in the Zurich release.

### What's new {#secops-container-vuln-resp-rn-release__secops-container-vuln-resp-rn-new-features}

[Import container vulnerability data with the Vulnerability Response Integration with Wiz](https://www.servicenow.com/docs/access?context=vr-wiz-exploring-host-cf&version=zurich&pubname=zurich-security-management&ft:locale=en-US)
:   Import configuration test results from Wiz to detect non-compliant cloud configurations. Findings are mapped to cloud test results (CTRs) in the Configuration Compliance application to help you enforce security policies and
    standards across your cloud environment.

[Enhancements to imported scanner results](https://www.servicenow.com/docs/access?context=cvr-remediation-task-overview&version=zurich&pubname=zurich-security-management&ft:locale=en-US)
:   Enhancements support more scanner data on imports. Namespaces and hierarchy cluster are considered and populated in the discovered container image \[sn_vul_container_image\] table if this data is imported.
{#secops-container-vuln-resp-rn-release__secops-container-vuln-resp-rn-new-features-1}

### What's changed {#secops-container-vuln-resp-rn-release__secops-container-vuln-resp-rn-changed-features}

[Configure maximum rows in related lists](https://www.servicenow.com/docs/access?context=vr-max-rows-rel-list&version=zurich&pubname=zurich-security-management&ft:locale=en-US)
:   To improve readability and performance, you can now limit the number of rows shown in related lists on forms by setting the system property sn_vul_cmn.related_list.set_max_row.
{#secops-container-vuln-resp-rn-release__secops-container-vuln-resp-rn-changed-features-1}

