Qualys TotalCloud 2.26.0 Release Updates
The Qualys TotalCloud 2.26.0 version introduces new capabilities, features, and updates, and is expected to be available by the end of July 2026.
Multi-Cloud Inventory Overview
Qualys TotalCloud now delivers a unified inventory view across AWS, Azure, GCP, and OCI, giving security and cloud teams a single pane of glass to discover, manage, and govern all cloud resources without switching between consoles. Eliminate visibility gaps, accelerate investigations, and strengthen asset governance across your entire multi-cloud estate through a single centralized interface.
Key Benefits:
- Unified multi-cloud visibility: View and manage cloud resources across AWS, Azure, GCP, and OCI from a single dashboard, no more context switching between cloud consoles.
- Faster investigations, stronger governance: Complete resource context in one place accelerates incident response and ensures no asset goes untracked across your multi-cloud environment.

Sensitive Data Scanning – PHI, PCI, PII
Qualys TotalCloud now surfaces and extends secret detection to include sensitive data findings directly within the detailed inventory of cloud-hosted workloads, giving security teams immediate visibility into PII, PHI, and PCI across multiple geography-specific formats, alongside asset inventory and security posture.
By correlating sensitive data exposure with resource context in a single unified view, teams can prioritize remediation faster and reduce the risk of data exposure across their cloud environment. This is currently supported on AWS and GCP cloud workloads.
Key Benefits:
- Comprehensive sensitive data discovery: Identify PII, PHI, and PCI data across multiple geography-specific formats within cloud-hosted workloads — surfaced directly in the TotalCloud inventory view alongside secrets, API keys, and credentials.
- Context-driven risk prioritization: Correlate sensitive data findings with asset inventory and security posture to focus remediation efforts on the highest-risk resources first.
TruRisk Insights Catalog
Users can now access the TruRisk Insights catalog, which enables them to explore, search, and understand the full range of insights designed to detect toxic risk combinations, identity risks, compliance gaps, and cloud misconfigurations.
The Insights tab continues to surface flagged findings across your cloud platforms based on active risky combinations, while the catalog gives teams full transparency into the breadth and depth of Qualys’ continuously expanding TruRisk intelligence library.
Key Benefits:
- Complete insight transparency: Access a centralized catalog of all TruRisk Insights in one place, understand what each insight detects, why it matters, and its potential business impact before it fires in your environment.
- Broader risk awareness: Explore the full scope of Qualys’ TruRisk intelligence library, from toxic risk combinations and identity risks to compliance gaps and cloud misconfigurations, ensuring no risk category goes unexamined.

CSPM Enhancements
Investigate Cloud Configurations
Qualys TotalCloud now empowers security teams to interactively investigate their entire cloud environment through a powerful, metadata-driven query experience, without scripting, CLI commands, or external tools. Search and analyze cloud resources using rich metadata, including resource properties, tags, identities, networking, and compliance attributes, all from a single intuitive interface.
What sets this apart is the ability to turn investigation into action, convert any query directly into a reusable custom security control using JQL (JSON Query Language), transforming a one-time investigation into a continuous, automated governance policy that proactively detects drift and enforces security standards at scale.
Key Benefits:
- Powerful metadata-driven investigations: Search and analyze cloud resources using comprehensive metadata, resource properties, tags, identities, networking, security configurations, and compliance attributes, all from a single query interface.
- No-code security investigations: Build complex cloud queries through an intuitive query builder with no scripting, SQL, or cloud-native CLI expertise required.
- From investigation to continuous control: Convert validated queries directly into reusable custom controls that continuously monitor your cloud environment for policy violations, closing the loop between investigation and enforcement.

Note: This feature is currently in beta (For AWS and Azure Cloud) and will be enabled upon request. Contact your Technical Account Manager (TAM) or Qualys Technical Support.
Azure Tags Visibility
Qualys TotalCloud has extended cloud tag support to cover all Azure resource types, enabling teams to filter and search resources using Azure Cloud tags directly within TotalCloud. This bridges the gap between cloud security findings and structured ticketing workflows, ensuring remediation ownership is clear, traceable, and aligned to how the business organizes its cloud estate.
Comprehensive Findings for Azure Virtual Machines
Qualys TotalCloud now delivers an enhanced inventory view for Azure Virtual Machines, bringing full parity with the existing AWS VM experience. A dedicated Vulnerabilities tab and new summary cards, covering Public IP, Without Agents, Docker Hosts, and With Vulnerabilities, provide intuitive, at-a-glance insights on the Virtual Machines listing page, reducing the clicks needed to surface critical workload context.
Expanded Inventory Coverage
Qualys TotalCloud continues to expand cloud security coverage with support for more AWS and Azure resource types in Cloud Inventory, enabling discovery, inventory, and security posture assessment across a broader range of cloud services. Compliance checks are automatically extended to all newly onboarded resources, helping security teams identify misconfigurations faster and strengthen governance across their multi-cloud infrastructure.
For OCI, TotalCloud now delivers comprehensive metadata for all inventory resources, previously available only via evaluations, organized into dedicated tabs including Summary, Tags, and Evaluated Controls, with full API access for programmatic usage.
CSPM Control Enhancements
New Controls and Title Updates
Qualys continuously monitors new security controls across cloud platforms. In this release, the following new controls have been added:
- AWS Cloud
- Approximately 18 new security controls under AWS build-time checks
- 23 new security controls under AWS run-time checks (Without Policy Attachment)
- Azure: 10 new security controls under Azure run-time checks (Without Policy Attachment)
- OCI: Approximately 2 new security controls for the Oracle Cloud Infrastructure Foundation Benchmark.
Deprecated Controls
When cloud providers deprecate specific services or features, the corresponding Qualys CSPM controls are also deprecated to maintain alignment.
For more information on impacted controls, refer to the control metadata for: AWS | Azure | GCP | OCI
| Cloud | Deprecated Controls | Reason for Deprecation |
| AWS | CID 400 – Ensure an IAM User does not have access to the console | New improved control (CID 715) has been introduced that covers the check of deprecated control. |
New Control Permissions
We have introduced many new controls (as mentioned in the above section) with the TotalCloud 2.26.0 release, and the required granular permissions for those control evaluations are listed below.
| Cloud Provider | Permissions |
| AWS | network-firewall:ListFirewallPolicies,network-firewall:DescribeFirewallPolicy network-firewall:DescribeRuleGroup,network-firewall:ListRuleGroups ec2:DescribeVpcs, ec2:DescribeVpcEndpoints, ec2:DescribeNetworkAcls rds:DescribeDBInstances, rds:DescribeDBParameters iam:ListUsers,iam:ListUserPolicies,iam:ListGroups iam:GenerateCredentialReport,iam:GetCredentialReport iam:ListVirtualMFADevices, iam:GetGroup,iam:ListAttachedUserPolicies iam:GetUser, iam:ListAccessKeys rds:ListTagsForResource, rds:DescribeDBInstances rds:DescribeDBParameters, autoscaling:DescribeLaunchConfigurations ec2:DescribeSecurityGroups,ec2:DescribeAddresses, ec2:DescribeNatGateways |
| Azure | Microsoft.Authorization/roleAssignments/read Microsoft.ApiManagement/service/read Microsoft.ApiManagement/service/apis/read Microsoft.MachineLearningServices/workspaces/read Microsoft.DBforMySQL/flexibleServers/read, Microsoft.DBforMySQL/flexibleServers/firewallRules/read Microsoft.Sql/managedInstances/read Microsoft.Resources/subscriptions/resourceGroups/read Microsoft.Sql/servers/read Microsoft.Compute/virtualMachineScaleSets/read Microsoft.ServiceBus/namespaces/read Microsoft.DocumentDB/databaseAccounts/read Microsoft.Network/applicationGateways/read |
New Inventory Permissions
We have introduced support for many new cloud services with the TotalCloud 2.26.0 release and the required granular permissions for the resource inventory, as listed below.
| Cloud Provider | Permissions |
| AWS | kms:ListKeys, kms:GetKeyPolicy, kms:GetKeyRotationStatus iam:GetAccountPasswordPolicy elasticache:DescribeReplicationGroups rds:DescribeDBClusterSnapshots, rds:DescribeDBClusters es:ListDomainNames,es:DescribeElasticsearchDomain kafka:ListClusters autoscaling:DescribeLaunchConfigurations cognito-identity:ListIdentityPools,cognito-identity:DescribeIdentityPool dms:DescribeReplicationInstances ec2:DescribeVpcPeeringConnections directconnect:DescribeConnections |
| Azure | Microsoft.Authorization/roleAssignments/read Microsoft.Databricks/workspaces/read Microsoft.MachineLearningServices/workspaces/read Microsoft.Network/routeTables/read, Microsoft.Network/virtualNetworks/read Microsoft.DesktopVirtualization/workspaces/read Microsoft.Sql/managedInstances/read Microsoft.Network/virtualNetworks/read Microsoft.Network/virtualNetworks/subnets/read Microsoft.Web/sites/Read, Microsoft.Web/sites/slots/Read, Microsoft.Web/hostingEnvironments/read Microsoft.ApiManagement/service/read |
For ongoing updates on control changes, refer to the TotalCloud Release Notes for version 2.26, which will be published soon on the Qualys Product Release Notes page.
Cloud Connector Enhancements
Workload Identity Federation Authentication for GCP Cloud
Qualys TotalCloud now supports Workload Identity Federation for onboarding Google Cloud connectors across the entire GCP Organization, enabling secure, keyless authentication with short-lived federated credentials instead of long-lived service account keys. This significantly reduces credential management overhead and minimizes the risk of credential compromise, making GCP connector onboarding both more secure and more streamlined.
Key Benefits:
- Keyless, secure authentication: Eliminate the need to create, store, and rotate long-lived service account keys; short-lived federated credentials handle authentication automatically.
- Simplified GCP onboarding: Streamline Google Cloud connector setup with trusted identity federation at the organization level, reducing manual key management and lowering the risk of credential theft or unauthorized access.

Note: This feature is currently in beta and will be enabled upon request. Contact your Technical Account Manager (TAM) or Qualys Technical Support.
Verify Permissions Before Deployment for OCI
Qualys TotalCloud now offers a Test Connector capability for Oracle Cloud Infrastructure (OCI), allowing administrators to validate connectivity, authentication, permissions, and API accessibility with a single click before initiating cloud discovery or security assessments. By catching configuration issues early, teams can onboard OCI environments faster, with greater confidence and significantly less troubleshooting effort.
Continue Your TotalCloud™ Journey
- Learn more about TotalCloud™ CNAPP, the Risk-minded CNAPP
- Request a Personalized TotalCloud™ Demo
- Start Your Free Trial of Qualys TotalCloud™
- Access the TotalCloud™ Online Help, Connectors Guide, and the TotalCloud API User Guide
- Watch the TotalCloud™ How-to Training Videos
If you have any questions, please contact your Technical Account Manager (TAM) or Qualys Technical Support.