Qualys TotalCloud 2.26.0 Release Updates

Vinayak Ghadi

The Qualys TotalCloud 2.26.0 version introduces new capabilities, features, and updates, and is expected to be available by the end of July 2026.

Multi-Cloud Inventory Overview

Qualys TotalCloud now delivers a unified inventory view across AWS, Azure, GCP, and OCI, giving security and cloud teams a single pane of glass to discover, manage, and govern all cloud resources without switching between consoles. Eliminate visibility gaps, accelerate investigations, and strengthen asset governance across your entire multi-cloud estate through a single centralized interface.

Key Benefits:

  • Unified multi-cloud visibility: View and manage cloud resources across AWS, Azure, GCP, and OCI from a single dashboard, no more context switching between cloud consoles.
  • Faster investigations, stronger governance: Complete resource context in one place accelerates incident response and ensures no asset goes untracked across your multi-cloud environment.

Sensitive Data Scanning – PHI, PCI, PII

Qualys TotalCloud now surfaces and extends secret detection to include sensitive data findings directly within the detailed inventory of cloud-hosted workloads, giving security teams immediate visibility into PII, PHI, and PCI across multiple geography-specific formats, alongside asset inventory and security posture. 

By correlating sensitive data exposure with resource context in a single unified view, teams can prioritize remediation faster and reduce the risk of data exposure across their cloud environment. This is currently supported on AWS and GCP cloud workloads.

Key Benefits:

  • Comprehensive sensitive data discovery: Identify PII, PHI, and PCI data across multiple geography-specific formats within cloud-hosted workloads — surfaced directly in the TotalCloud inventory view alongside secrets, API keys, and credentials.
  • Context-driven risk prioritization: Correlate sensitive data findings with asset inventory and security posture to focus remediation efforts on the highest-risk resources first.

TruRisk Insights Catalog

Users can now access the TruRisk Insights catalog, which enables them to explore, search, and understand the full range of insights designed to detect toxic risk combinations, identity risks, compliance gaps, and cloud misconfigurations. 

The Insights tab continues to surface flagged findings across your cloud platforms based on active risky combinations, while the catalog gives teams full transparency into the breadth and depth of Qualys’ continuously expanding TruRisk intelligence library.

Key Benefits:

  • Complete insight transparency: Access a centralized catalog of all TruRisk Insights in one place, understand what each insight detects, why it matters, and its potential business impact before it fires in your environment.
  • Broader risk awareness: Explore the full scope of Qualys’ TruRisk intelligence library, from toxic risk combinations and identity risks to compliance gaps and cloud misconfigurations, ensuring no risk category goes unexamined.

CSPM Enhancements

Investigate Cloud Configurations

Qualys TotalCloud now empowers security teams to interactively investigate their entire cloud environment through a powerful, metadata-driven query experience, without scripting, CLI commands, or external tools. Search and analyze cloud resources using rich metadata, including resource properties, tags, identities, networking, and compliance attributes, all from a single intuitive interface.

What sets this apart is the ability to turn investigation into action, convert any query directly into a reusable custom security control using JQL (JSON Query Language), transforming a one-time investigation into a continuous, automated governance policy that proactively detects drift and enforces security standards at scale.

Key Benefits:

  • Powerful metadata-driven investigations: Search and analyze cloud resources using comprehensive metadata, resource properties, tags, identities, networking, security configurations, and compliance attributes, all from a single query interface.
  • No-code security investigations: Build complex cloud queries through an intuitive query builder with no scripting, SQL, or cloud-native CLI expertise required.
  • From investigation to continuous control: Convert validated queries directly into reusable custom controls that continuously monitor your cloud environment for policy violations, closing the loop between investigation and enforcement.

Note: This feature is currently in beta (For AWS and Azure Cloud) and will be enabled upon request. Contact your Technical Account Manager (TAM) or Qualys Technical Support.

Azure Tags Visibility

Qualys TotalCloud has extended cloud tag support to cover all Azure resource types, enabling teams to filter and search resources using Azure Cloud tags directly within TotalCloud. This bridges the gap between cloud security findings and structured ticketing workflows, ensuring remediation ownership is clear, traceable, and aligned to how the business organizes its cloud estate.

Comprehensive Findings for Azure Virtual Machines

Qualys TotalCloud now delivers an enhanced inventory view for Azure Virtual Machines, bringing full parity with the existing AWS VM experience. A dedicated Vulnerabilities tab and new summary cards, covering Public IP, Without Agents, Docker Hosts, and With Vulnerabilities, provide intuitive, at-a-glance insights on the Virtual Machines listing page, reducing the clicks needed to surface critical workload context.

Expanded Inventory Coverage 

Qualys TotalCloud continues to expand cloud security coverage with support for more AWS and Azure resource types in Cloud Inventory, enabling discovery, inventory, and security posture assessment across a broader range of cloud services. Compliance checks are automatically extended to all newly onboarded resources, helping security teams identify misconfigurations faster and strengthen governance across their multi-cloud infrastructure. 

For OCI, TotalCloud now delivers comprehensive metadata for all inventory resources, previously available only via evaluations, organized into dedicated tabs including Summary, Tags, and Evaluated Controls, with full API access for programmatic usage.

CSPM Control Enhancements

New Controls and Title Updates

Qualys continuously monitors new security controls across cloud platforms. In this release, the following new controls have been added:

  • AWS Cloud
  • Approximately 18 new security controls under AWS build-time checks
  • 23 new security controls under AWS run-time checks (Without Policy Attachment)
  • Azure: 10 new security controls under Azure run-time checks (Without Policy Attachment)
  • OCI: Approximately 2 new security controls for the Oracle Cloud Infrastructure Foundation Benchmark.

Deprecated Controls

When cloud providers deprecate specific services or features, the corresponding Qualys CSPM controls are also deprecated to maintain alignment. 

For more information on impacted controls, refer to the control metadata forAWS | Azure | GCP | OCI

Cloud Deprecated ControlsReason for Deprecation
AWSCID 400 – Ensure an IAM User does not have access to the consoleNew improved control (CID 715) has been introduced that covers the check of deprecated control.

New Control Permissions

We have introduced many new controls (as mentioned in the above section) with the TotalCloud 2.26.0 release, and the required granular permissions for those control evaluations are listed below.

Cloud ProviderPermissions
AWSnetwork-firewall:ListFirewallPolicies,network-firewall:DescribeFirewallPolicy
network-firewall:DescribeRuleGroup,network-firewall:ListRuleGroups 
ec2:DescribeVpcs, ec2:DescribeVpcEndpoints, ec2:DescribeNetworkAcls 
rds:DescribeDBInstances, rds:DescribeDBParameters 
iam:ListUsers,iam:ListUserPolicies,iam:ListGroups
iam:GenerateCredentialReport,iam:GetCredentialReport
iam:ListVirtualMFADevices, iam:GetGroup,iam:ListAttachedUserPolicies
iam:GetUser, iam:ListAccessKeys 
rds:ListTagsForResource, rds:DescribeDBInstances
rds:DescribeDBParameters, autoscaling:DescribeLaunchConfigurations
ec2:DescribeSecurityGroups,ec2:DescribeAddresses, ec2:DescribeNatGateways
AzureMicrosoft.Authorization/roleAssignments/read 
Microsoft.ApiManagement/service/read
Microsoft.ApiManagement/service/apis/read 
Microsoft.MachineLearningServices/workspaces/read
Microsoft.DBforMySQL/flexibleServers/read,
Microsoft.DBforMySQL/flexibleServers/firewallRules/read 
Microsoft.Sql/managedInstances/read
Microsoft.Resources/subscriptions/resourceGroups/read
Microsoft.Sql/servers/read 
Microsoft.Compute/virtualMachineScaleSets/read
Microsoft.ServiceBus/namespaces/read
Microsoft.DocumentDB/databaseAccounts/read
Microsoft.Network/applicationGateways/read

New Inventory Permissions

We have introduced support for many new cloud services with the  TotalCloud 2.26.0 release and the required granular permissions for the resource inventory, as listed below.

Cloud ProviderPermissions
AWSkms:ListKeys, kms:GetKeyPolicy, kms:GetKeyRotationStatus 
iam:GetAccountPasswordPolicy
elasticache:DescribeReplicationGroups
rds:DescribeDBClusterSnapshots, rds:DescribeDBClusters
es:ListDomainNames,es:DescribeElasticsearchDomain 
kafka:ListClusters
autoscaling:DescribeLaunchConfigurations
cognito-identity:ListIdentityPools,cognito-identity:DescribeIdentityPool
dms:DescribeReplicationInstances
ec2:DescribeVpcPeeringConnections
directconnect:DescribeConnections
AzureMicrosoft.Authorization/roleAssignments/read 
Microsoft.Databricks/workspaces/read
Microsoft.MachineLearningServices/workspaces/read
Microsoft.Network/routeTables/read, Microsoft.Network/virtualNetworks/read
Microsoft.DesktopVirtualization/workspaces/read
Microsoft.Sql/managedInstances/read
Microsoft.Network/virtualNetworks/read
Microsoft.Network/virtualNetworks/subnets/read
Microsoft.Web/sites/Read, Microsoft.Web/sites/slots/Read, Microsoft.Web/hostingEnvironments/read
Microsoft.ApiManagement/service/read

For ongoing updates on control changes, refer to the TotalCloud Release Notes for version 2.26, which will be published soon on the Qualys Product Release Notes page.

Cloud Connector Enhancements

Workload Identity Federation Authentication for GCP Cloud

Qualys TotalCloud now supports Workload Identity Federation for onboarding Google Cloud connectors across the entire GCP Organization, enabling secure, keyless authentication with short-lived federated credentials instead of long-lived service account keys. This significantly reduces credential management overhead and minimizes the risk of credential compromise, making GCP connector onboarding both more secure and more streamlined.

Key Benefits:

  • Keyless, secure authentication: Eliminate the need to create, store, and rotate long-lived service account keys; short-lived federated credentials handle authentication automatically.
  • Simplified GCP onboarding: Streamline Google Cloud connector setup with trusted identity federation at the organization level, reducing manual key management and lowering the risk of credential theft or unauthorized access.

Note: This feature is currently in beta and will be enabled upon request. Contact your Technical Account Manager (TAM) or Qualys Technical Support.

Verify Permissions Before Deployment for OCI

Qualys TotalCloud now offers a Test Connector capability for Oracle Cloud Infrastructure (OCI), allowing administrators to validate connectivity, authentication, permissions, and API accessibility with a single click before initiating cloud discovery or security assessments. By catching configuration issues early, teams can onboard OCI environments faster, with greater confidence and significantly less troubleshooting effort.

Continue Your TotalCloud™ Journey

If you have any questions, please contact your Technical Account Manager (TAM) or Qualys Technical Support.

Share your Comments

Comments

Your email address will not be published. Required fields are marked *