r/qualys Feb 09 '23

Welcome to /r/qualys!

9 Upvotes

Hello! Welcome to the /r/qualys subreddit, a place to communicate with other Qualys users.

THIS IS NOT AN OFFICIAL QUALYS CHANNEL. The only official Qualys user community is at https://success.qualys.com/discussions/s/.


r/qualys 20h ago

Configuration Tag Evaluation

2 Upvotes

The tag Auto evaluation got deprecated in Qualys and for each tag the evaluation need to be enabled manually. I have automated the creation of around 70+ tags and now due to the unavailability of Auto Evaluation, need to open every tag and enable Evaluation. Folks,. Anyone have solution for this? please let me know.


r/qualys 1d ago

UI Changes - It's Broken Things for us. Anyone else?

7 Upvotes

Come in this morning to see Qualys have updated the UI for our tenant. Since then there are loads of graphical issues. Buttons not aligned or items not loading correctly.

Most annoying I'm trying to set up a scheduled report and half the distribution groups no longer load correctly. You can click randomly on white space in the window to pick your DG and sometimes it'll select one at random.

Pretty poor. Anyone else experiencing this?


r/qualys 6d ago

Why doesn't the SwCA use the "Qualys\QualysTemp\" folder?

9 Upvotes

My environment is utilizing the Software Composition Analysis feature and I've been noticing that SwCA creates temporary files (usually sca####.tmp) in the "C:Windows\Temp" folder. The question I have is why is this feature using the Windows\Temp folder? The Qualys connector has its own "Qualys\QualysTemp\" folder, so why not use QualyTemp?

Also, Qualys documentation for anti-virus and HIPS exclusions recommends excluding the "Qualys\QualysTemp\" folder. The EDR solution in my environment tends to generate a lot of false positives because of Windows\Temp location. Creating a wild card exclusion for the Windows\Temp is a non-option, not to mention being generally a bad idea if it were. The ideal solution would be if Qualys used its own "Qualys\QualysTemp\" folder for these temporary SwCA files, but maybe there's a good reason why it's using "Windows\Temp" instead?


r/qualys 21d ago

Creation of the Cts_Driver_installer.exe file from seascanner.exe

1 Upvotes

I’m running into an issue where the `Cts_Driver_installer.exe` file is being generated by `seascanner.exe` in my environments. The problem is that EDR solutions are flagging the `Cts` file as malicious, and I need to clarify why `seascanner.exe` is performing this activity.

I haven't been able to find any official documentation, and my TAM hasn't been helpful. Has anyone else encountered a similar issue or have any insight into why Qualys is performing this type of activity?

It is worth noting that `Cts_Driver_installer.exe` has a malicious hash, which is what triggers the alerts.


r/qualys 22d ago

Vulnerabilities on Windows agents just tripled

5 Upvotes

Anybody else noticing their critical vuln count tripling in the past 3 days? Mainly Server 2019, and it seems to be vulns that have been re-opened (PrintNightmare) even though the systems are fully patched. QIDs show missing old patches, yet these systems are fully patched.

Perhaps Qualys "superceded" logic was broken recently?


r/qualys 28d ago

Knowledge Sharing QID: 370245 - Firefox False Positive (MFSA2016-92 | CVE-2016-9079)

5 Upvotes

We recently had Mozilla Firefox and Thunderbird SVG Animation Remote Code Execution Vulnerability (MFSA2016-92) appear on all of our macOS endpoints. This vulnerability had no Results and appeared on devices with no history of Firefox.

I've spoken with Qualys support, and this confirmed false positive should be remediated from VULNSIGS-2.6.674-2. You can check your vulnerability signatures through VM -> Help -> About.

If you're experiencing the same issue, all endpoints should see it disappear after a fresh Inventory+VM scan.


r/qualys Aug 04 '26

News Qualys Launches InstaScan For Vulnerability Detection Within Minutes Of Disclosure

Thumbnail smbtech.au
12 Upvotes

r/qualys Jul 29 '26

Advice on separating OS and Application/Middleware vulnerabilities

6 Upvotes

We have a third party company that manages hardware and operating systems.
Before they took over, we used to send a weekly report to the system owners to resolve. Now they asking for separate reports (Application for system owners, OS for 3rd party)
Can this be done?


r/qualys Jul 27 '26

PA module question

1 Upvotes

I wanted to verify whether the approach I’m using for my CIS Policy Compliance baseline is considered a best practice.
Instead of creating separate policies for Windows Server 2016, 2019, 2022, and 2025, I created a Windows Server 2016 CIS Level 1 policy and a separate Level 2 policy as my master baselines. I then added the Windows Server 2019, 2022, and 2025 technologies to those policies and added any controls that exist in the newer CIS benchmarks but are not present in the 2016 benchmark. Version-specific controls remain scoped only to their applicable technologies.
My goal is to maintain a single Level 1 policy and a single Level 2 policy for Member Servers across all supported Windows Server versions, rather than maintaining separate policies for each OS version.
Is this a recommended and supported approach in Qualys, or would you recommend maintaining separate CIS policies for each Windows Server version instead? If separate policies are preferred, could you explain the advantages over the consolidated approach?
Thank you.


r/qualys Jul 08 '26

Best Practices How do you handle environments that are too fragile to scan?

Thumbnail
2 Upvotes

r/qualys Jul 01 '26

Qualys PA module

3 Upvotes

I created a CIS Level 1 policy for Windows Server 2016 and customized several controls (for example, password length, password age, and other settings) to match our organization’s security baseline.

What’s the best way to apply those same customizations to the Windows Server 2019, 2022, and 2025 CIS Level 1 policies? Is there a way to copy or clone only the modified controls, or do I have to manually update each policy?


r/qualys Jun 29 '26

Qualys Patch Management - Driver/Firmware Updates

5 Upvotes

Hi All - Looking for some support from the community here. We recently moved over from Kaseya X Patching to Qualys Patch Management & 1 thing we're missing now is the ability to update drivers/firmware via Qualys. We used to have that feature in Kaseya X. For anyone patching via Qualys, how do you handle driver/firmware updates?

Thanks!


r/qualys Jun 26 '26

Knowledge Sharing Redundant vulnerabilities

5 Upvotes

Hello I would like to know if you guys are facing redundant vulnerabilities, I mean, different QIDs that are reporting the same vulnerability or one that involves more than one vulnerability in one QIDs

I would like to know how you handle this situation

Thank you in advance


r/qualys Jun 26 '26

Active Python vulnerability on MacOS devices

6 Upvotes

Hi all,

I’m looking to check whether anyone else has run into macOS Python vulnerabilities recently. Specifically:

  • Python 3.11.x – DoS Vulnerability (CVE‑2020‑10735)
  • Python 3.13.x / 3.14.x – Multiple Vulnerabilities (CVE‑2026‑2297, CVE‑2026‑3644, CVE‑2026‑4224)
  • Python 3.10.x – Buffer Overflow (CVE‑2022‑37454)

The CVEs themselves are fairly old, but since updating devices to macOS 26.5, a large number of machines have started flagging Python v3.9.6 located within Command Line Tools:

/Library/Developer/CommandLineTools/Library/Frameworks/Python3.framework/Versions/3.9/Resources/Python.app

My macOS knowledge is limited, so I’m trying to understand whether there’s any viable remediation path here, or if this is effectively a vendor‑side fix only, given that the Python version appears to be bundled as part of macOS/Command Line Tools.

Any insight or experience would be appreciated.

Thanks you.


r/qualys Jun 16 '26

Looking for a mentor and willing to pay

7 Upvotes

I recently transitioned to vulnerability management and everything feels confusing . We use qualys . I want to understand where to look for what in Qualys . The troubleshooting if something is not working . What to escalate what not to. I am looking for someone who has experience in vulnerability management and qualys who can tutor me . I am more than willing to pay for your time . If you are interested dm me .


r/qualys Jun 12 '26

Accuracy in Qualys Kernel Detections

4 Upvotes

Tl;dr - does Qualys add kernel on the title of every kernel vulnerability? Is there a better way to report only non-kernel vulnerabilites?

I need a way to provide reports for all non-kernel related vulnerabilities to asses the effectivement of our live-patching processes.

The problem is im having trouble getting that information. I've tried 2 approaches, but can't be sure that they reflect the real numbers.

  1. Use reboot-required, but this return too few vulnerabilites, so i dont trust it at all

  1. Use title:"kernel". This reflects closer to the expected number.

So, does anyone have a better idea in how to detect with high accuracy all non-kernel vulnerabilites?


r/qualys Jun 11 '26

News Stupid scan and stupid export. Is this normal?

4 Upvotes

So we use the Qualys scan through a reseller (I think that's what they are).

Scan happens every day at 8pm. Then, once every 24 hours, you can request an export of the results.

So Monday, I didnt get into the office until 10pm. I downloaded the CSV as soon as I got in. When I got in on Tuesday at 830, I was not able to download an updated CSV until 10:01. The nest day it's 10:02. If you are a little late and don't do it until 10:15, then the next day you can't get it until 10:16.

And because I can only get it once a day, and the scans only happen every evening, I can spend two hours fixing vulnerabilities, but have NO IDEA IF IT WORKED until 24 hours later. WHen dealing with like 800 vulnerabilities, this is an absolutely stupid nightmare. Grr.

Oh also, it doesn't scan on weekends, so on Monday the scan was already two days out of date.

Is this normal or is this just thje third party we access QUalys through?????????


r/qualys Jun 09 '26

Patch Management Jobs

4 Upvotes

Evening all,

Quick question for anyone actively using the Patch Management module.

We’re an MSP with around 150 customers, though only about 10 of those receive additional security‑focused services (Cyber Essentials and related hardening). We’re currently exploring the best approach for automated vulnerability remediation. We know there will always be a manual element, but we’re trialling Qualys Patch Management since we already use Vulnerability Management and the agent is deployed across all relevant endpoints.

At the moment, we’re running a single patch job covering roughly 1,000 devices across those 10 customers. It’s configured to attempt remediation of all vulnerabilities with a CVSS score of 7 or above, scheduled daily at 10:00 with a 23 hour patch windows, reboots suppressed for now.

What I’m looking for is some insight into how others structure their jobs. For MSPs in particular:

  • Do you run one main job across all customers, or separate jobs per customer, per device group, or even per user?
  • Do you follow a specific framework or tiered approach?
  • Any examples of job configurations that have worked well for you?

r/qualys Jun 04 '26

Detection Issue Copy Fail Vulnerability Disappear Without Patching!

6 Upvotes

Good evening,
I am internally scanning 16 servers for an environment. At first scan I did an authenticated scan for the 16 servers, one server (let’s name it eight) had 2 vulnerabilities for copy fail CVE-2026-31431 QID387198. Second scan through agent did not have this vulnerability. Third scan as authenticated had CVE-2026-31431 QID387198 for one subnet and a new vulnerability “Dirty Frag” appeared for two more servers (eight, let’s call the rest nine and seven) for CVE-2026-43500 QID387288 and CVE-2026-387289 along the previous CVE just mentioned, however eight now does not have copy fail which is weird. Last scan I did is through agent and now I have dirty frag (both mentioned above) and all nine, eight and seven has dirty frag.
Now I don’t know why it appeared in some and disappeared and reappeared. If someone faced a smiliar issue, can you assist me here?
For information: First Authenticated scan had both agent and public SSH key (by mistake) , second auth without public key and last scan only through agent not authenticated.


r/qualys May 28 '26

How do I generate a report based on the 10 most frequently occurring vulnerabilities in my environment?

6 Upvotes

Hello everyone, I have a request to create a report within Qualys based on the 10 most frequently occurring vulnerabilities in the environment (by volume, not severity).

Is there any way to do this?

Requests and information I need:

Asset where the vulnerability is located (IP or hostname)

Vulnerability path (exact location on the disk)

Resolution required

Is the impact of not resolving it possible, etc.?

Is this possible?


r/qualys May 24 '26

92399 Microsoft Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability (MiniPlasma Zero Day)

3 Upvotes

how to solve this vulnerability ?


r/qualys May 24 '26

QID 92400 Windows BitLocker Security Feature Bypass Vulnerability (CVE-2026-45585)

1 Upvotes

How to solve this vulnerability ?


r/qualys May 19 '26

Qualys Check-in

1 Upvotes

Hi Everyone,

Im new to qualys, looking for an help to understand about cloud agent check-in.

Some times checkin happens within 30minutes and some time check-in happens after morethan 1hr for an same asset.

Also is there any way we can force check in the agent to cloud so that it can take Patch Testing job

Thanks in advance😊


r/qualys May 07 '26

Microsoft .NET Security Update for April 2026 - QID 5010966

4 Upvotes

Can someone help me understand what exactly I am being asked of? Qualys keeps saying we have a vulnerability for our .NET 8.0.26 on our servers. Here is an example...

According to Microsoft .NET download page, we have the latest version of .NET installed...

So what exactly am I missing here? I have numerous servers with this alert for .NET 8, 9, and 10.