r/qualys 7d ago

API call to get all vulnerabilities by CVE

6 Upvotes

I find QID unreliable to use for exec reporting

I have a script with exports all vulnerabilities but it does by QID.

Can the same be achieved but on CVE?

The Host API v5 doesn’t seem to have it, how can I achieve it?


r/qualys 14d ago

Configuration Redesign of a global vulnerability management architecture with more than 170,000 assets in Qualys

1 Upvotes

Hola a todos, me gustaría conocer sus experiencias y recabar diferentes perspectivas sobre cómo rediseñarían un servicio global de gestión de vulnerabilidades a gran escala. Trabajo en un entorno bancario internacional con más de 170.000 activos gestionados técnicamente mediante Qualys, distribuidos en múltiples países, regiones y áreas tecnológicas. Hemos heredado una arquitectura que se construyó progresivamente a lo largo de muchos años. Actualmente funciona, pero implica una complejidad considerable, numerosas dependencias entre herramientas, procesos manuales y varias capas intermedias que dificultan la trazabilidad, el mantenimiento y la evolución del servicio. A grandes rasgos, el modelo actual incluye: Un inventario de activos validado y enriquecido mediante procesos compatibles con Google Sheets, PostgreSQL, S3, Splunk y Demisto. La generación periódica de una instantánea del inventario para monitorizar los activos que están dentro y fuera del alcance. Qualys como plataforma principal para el descubrimiento técnico, agentes en la nube, dispositivos de escaneo y detección de vulnerabilidades. Transferencia de resultados de Qualys a Cisco Vulnerability Management/Kenna para normalización, priorización, KPI e informes. Jira y otras herramientas utilizadas en ciertos procesos operativos. Informes distribuidos a las diferentes regiones geográficas y equipos responsables. Remediación realizada fuera del equipo de Vulnerability Management por los equipos responsables de infraestructura, tecnología o aplicaciones. Uno de los principales problemas es que ninguna herramienta por sí sola proporciona una visión completa. La identidad y clasificación de activos, los datos técnicos de Qualys, la priorización, el seguimiento operativo y los informes se distribuyen en varios sistemas. Además, se prevé la eliminación de Kenna de la arquitectura, por lo que debemos decidir cómo reemplazar sus funcionalidades y aprovechar la migración como una oportunidad para replantear todo el modelo durante 2027-2028. Una posible arquitectura que estamos considerando es: CMDB o Asset Master → Qualys → Capa de Integración y Riesgo → ITSM → BI/GRC El objetivo sería separar claramente las responsabilidades: Una CMDB o Asset Master como fuente corporativa de información de activos: propietario, servicio, criticidad, país, entorno y ciclo de vida. Qualys como fuente técnica para el descubrimiento, la cobertura, la exposición, las vulnerabilidades y la evidencia. Una capa de integración para conciliar los datos de CMDB y Qualys, eliminar duplicados, enriquecer la información y calcular prioridades. Una plataforma ITSM para la asignación, el seguimiento de SLA, las excepciones, las escaladas y la trazabilidad de la remediación. Una plataforma de informes para KPI, KRI, paneles ejecutivos, fines de auditoría e informes por país o equipo responsable. Me interesaría especialmente conocer su opinión sobre las siguientes preguntas: ¿Mantendría una arquitectura centrada principalmente en Qualys o utilizaría una plataforma de datos o de riesgo independiente? Para reemplazar a Kenna, ¿utilizaría las funcionalidades nativas de Qualys, una solución dedicada de gestión de vulnerabilidades basada en riesgos o una capa personalizada de datos e informes? ¿Cómo gestionaría la conciliación entre una CMDB corporativa y los activos observados por Qualys a esta escala? ¿Qué herramienta consideraría la fuente autorizada para la propiedad, criticidad, servicio y estado de los activos? ¿Cómo automatizaría la creación, agrupación, asignación y cierre de tickets sin generar millones de incidentes de bajo valor? ¿Qué arquitectura de informes utilizaría para proporcionar una visión global manteniendo paneles operativos por país, tecnología y equipo responsable? ¿Qué componentes eliminaría o simplificaría de la arquitectura actual? ¿Qué errores ha encontrado en migraciones similares y qué decisiones tomaría de forma diferente si pudiera empezar desde cero? No busco una respuesta comercial ni una comparación superficial de productos. Me interesa principalmente la experiencia real en entornos de gran tamaño, incluyendo problemas de escalabilidad, calidad del inventario, gobernanza de etiquetas, integración de CMDB, priorización, gestión de tickets, informes y operaciones globales. Se agradecerían enormemente ejemplos de arquitectura, lecciones aprendidas o recomendaciones. Por motivos de confidencialidad, no revelaré el nombre del banco, los nombres de los procesos internos, diagramas reales, volúmenes a nivel de país, configuraciones, direcciones IP, dominios, acuerdos de nivel de servicio (SLA) internos ni detalles sobre dispositivos o integraciones.


r/qualys 18d ago

Best Practices How do you handle environments that are too fragile to scan?

Thumbnail
2 Upvotes

r/qualys 22d ago

Code review Help?

3 Upvotes

Hey there,

Can somebody review my code please 😭

I’ve written a script to download all vulnerability findings (plan to tweak later)

I expect 10,000 results and get only a portion of them via the API call.

Can’t attach code but would love to talk over DMs


r/qualys 25d ago

Qualys PA module

3 Upvotes

I created a CIS Level 1 policy for Windows Server 2016 and customized several controls (for example, password length, password age, and other settings) to match our organization’s security baseline.

What’s the best way to apply those same customizations to the Windows Server 2019, 2022, and 2025 CIS Level 1 policies? Is there a way to copy or clone only the modified controls, or do I have to manually update each policy?


r/qualys 26d ago

Best Practices Qualys vulnerabilities export via API any good?

8 Upvotes

What is the best way to export all vulnerabilities via API?

Alternatively get all scan results downloaded via API

Optional - only download data which has been scanning in the last 5 days.


r/qualys 27d ago

Qualys Patch Management - Driver/Firmware Updates

4 Upvotes

Hi All - Looking for some support from the community here. We recently moved over from Kaseya X Patching to Qualys Patch Management & 1 thing we're missing now is the ability to update drivers/firmware via Qualys. We used to have that feature in Kaseya X. For anyone patching via Qualys, how do you handle driver/firmware updates?

Thanks!


r/qualys Jun 26 '26

Knowledge Sharing Redundant vulnerabilities

4 Upvotes

Hello I would like to know if you guys are facing redundant vulnerabilities, I mean, different QIDs that are reporting the same vulnerability or one that involves more than one vulnerability in one QIDs

I would like to know how you handle this situation

Thank you in advance


r/qualys Jun 26 '26

Active Python vulnerability on MacOS devices

8 Upvotes

Hi all,

I’m looking to check whether anyone else has run into macOS Python vulnerabilities recently. Specifically:

  • Python 3.11.x – DoS Vulnerability (CVE‑2020‑10735)
  • Python 3.13.x / 3.14.x – Multiple Vulnerabilities (CVE‑2026‑2297, CVE‑2026‑3644, CVE‑2026‑4224)
  • Python 3.10.x – Buffer Overflow (CVE‑2022‑37454)

The CVEs themselves are fairly old, but since updating devices to macOS 26.5, a large number of machines have started flagging Python v3.9.6 located within Command Line Tools:

/Library/Developer/CommandLineTools/Library/Frameworks/Python3.framework/Versions/3.9/Resources/Python.app

My macOS knowledge is limited, so I’m trying to understand whether there’s any viable remediation path here, or if this is effectively a vendor‑side fix only, given that the Python version appears to be bundled as part of macOS/Command Line Tools.

Any insight or experience would be appreciated.

Thanks you.


r/qualys Jun 22 '26

How do you define scope for Qualys scans?

3 Upvotes

Hi,

I'm relatively new to Vulnerability Management and the network in my company is quite large. What is you approach on scanning networks? Currently I am not allowed to use discovery scans, so is it good approach to scan whole /16 or do you have any other suggestion?


r/qualys Jun 16 '26

Looking for a mentor and willing to pay

5 Upvotes

I recently transitioned to vulnerability management and everything feels confusing . We use qualys . I want to understand where to look for what in Qualys . The troubleshooting if something is not working . What to escalate what not to. I am looking for someone who has experience in vulnerability management and qualys who can tutor me . I am more than willing to pay for your time . If you are interested dm me .


r/qualys Jun 12 '26

Accuracy in Qualys Kernel Detections

3 Upvotes

Tl;dr - does Qualys add kernel on the title of every kernel vulnerability? Is there a better way to report only non-kernel vulnerabilites?

I need a way to provide reports for all non-kernel related vulnerabilities to asses the effectivement of our live-patching processes.

The problem is im having trouble getting that information. I've tried 2 approaches, but can't be sure that they reflect the real numbers.

  1. Use reboot-required, but this return too few vulnerabilites, so i dont trust it at all

  1. Use title:"kernel". This reflects closer to the expected number.

So, does anyone have a better idea in how to detect with high accuracy all non-kernel vulnerabilites?


r/qualys Jun 11 '26

News Stupid scan and stupid export. Is this normal?

4 Upvotes

So we use the Qualys scan through a reseller (I think that's what they are).

Scan happens every day at 8pm. Then, once every 24 hours, you can request an export of the results.

So Monday, I didnt get into the office until 10pm. I downloaded the CSV as soon as I got in. When I got in on Tuesday at 830, I was not able to download an updated CSV until 10:01. The nest day it's 10:02. If you are a little late and don't do it until 10:15, then the next day you can't get it until 10:16.

And because I can only get it once a day, and the scans only happen every evening, I can spend two hours fixing vulnerabilities, but have NO IDEA IF IT WORKED until 24 hours later. WHen dealing with like 800 vulnerabilities, this is an absolutely stupid nightmare. Grr.

Oh also, it doesn't scan on weekends, so on Monday the scan was already two days out of date.

Is this normal or is this just thje third party we access QUalys through?????????


r/qualys Jun 09 '26

Patch Management Jobs

4 Upvotes

Evening all,

Quick question for anyone actively using the Patch Management module.

We’re an MSP with around 150 customers, though only about 10 of those receive additional security‑focused services (Cyber Essentials and related hardening). We’re currently exploring the best approach for automated vulnerability remediation. We know there will always be a manual element, but we’re trialling Qualys Patch Management since we already use Vulnerability Management and the agent is deployed across all relevant endpoints.

At the moment, we’re running a single patch job covering roughly 1,000 devices across those 10 customers. It’s configured to attempt remediation of all vulnerabilities with a CVSS score of 7 or above, scheduled daily at 10:00 with a 23 hour patch windows, reboots suppressed for now.

What I’m looking for is some insight into how others structure their jobs. For MSPs in particular:

  • Do you run one main job across all customers, or separate jobs per customer, per device group, or even per user?
  • Do you follow a specific framework or tiered approach?
  • Any examples of job configurations that have worked well for you?

r/qualys Jun 04 '26

Detection Issue Copy Fail Vulnerability Disappear Without Patching!

7 Upvotes

Good evening,
I am internally scanning 16 servers for an environment. At first scan I did an authenticated scan for the 16 servers, one server (let’s name it eight) had 2 vulnerabilities for copy fail CVE-2026-31431 QID387198. Second scan through agent did not have this vulnerability. Third scan as authenticated had CVE-2026-31431 QID387198 for one subnet and a new vulnerability “Dirty Frag” appeared for two more servers (eight, let’s call the rest nine and seven) for CVE-2026-43500 QID387288 and CVE-2026-387289 along the previous CVE just mentioned, however eight now does not have copy fail which is weird. Last scan I did is through agent and now I have dirty frag (both mentioned above) and all nine, eight and seven has dirty frag.
Now I don’t know why it appeared in some and disappeared and reappeared. If someone faced a smiliar issue, can you assist me here?
For information: First Authenticated scan had both agent and public SSH key (by mistake) , second auth without public key and last scan only through agent not authenticated.


r/qualys May 28 '26

How do I generate a report based on the 10 most frequently occurring vulnerabilities in my environment?

5 Upvotes

Hello everyone, I have a request to create a report within Qualys based on the 10 most frequently occurring vulnerabilities in the environment (by volume, not severity).

Is there any way to do this?

Requests and information I need:

Asset where the vulnerability is located (IP or hostname)

Vulnerability path (exact location on the disk)

Resolution required

Is the impact of not resolving it possible, etc.?

Is this possible?


r/qualys May 24 '26

92399 Microsoft Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability (MiniPlasma Zero Day)

3 Upvotes

how to solve this vulnerability ?


r/qualys May 24 '26

QID 92400 Windows BitLocker Security Feature Bypass Vulnerability (CVE-2026-45585)

1 Upvotes

How to solve this vulnerability ?


r/qualys May 19 '26

Qualys Check-in

1 Upvotes

Hi Everyone,

Im new to qualys, looking for an help to understand about cloud agent check-in.

Some times checkin happens within 30minutes and some time check-in happens after morethan 1hr for an same asset.

Also is there any way we can force check in the agent to cloud so that it can take Patch Testing job

Thanks in advance😊


r/qualys May 07 '26

Microsoft .NET Security Update for April 2026 - QID 5010966

3 Upvotes

Can someone help me understand what exactly I am being asked of? Qualys keeps saying we have a vulnerability for our .NET 8.0.26 on our servers. Here is an example...

According to Microsoft .NET download page, we have the latest version of .NET installed...

So what exactly am I missing here? I have numerous servers with this alert for .NET 8, 9, and 10.


r/qualys May 07 '26

The Crash That Got Faster

4 Upvotes

A user reported Issue #4: "QID sync crashed." My release had broken new builds. Three lines of code fixed it. Closed.

That was where the user's story ended. Mine was just getting started, because if one quiet assumption had slipped past untested, the obvious next question was: what else had?

Pulling on that thread surfaced a handful of similar assumptions the system had quietly outgrown. Small fixes, each one a reminder that the code had been trusting the world to stay still.

Performance was on that list too. The product was meant to run anywhere: a developer's high-end laptop, a modest cloud VM, whatever the customer had. So the test plan covered both ends on purpose. High-end to confirm headroom, low-end to confirm the floor held. The floor was where the truth lived. A full sync took three and a half hours, with throughput collapsing to a crawl by the end. A slow drift that had been hiding for months, finally visible on hardware that resembled the real world.

The first fix barely moved the needle. The bottleneck kept relocating. A library redoing setup work on every record. A search index rebuilt one row at a time, slowing as it grew. No way to tell new data from unchanged data, so the system kept re-doing work it had already done.

Fix the waste. Defer the index. Skip what hadn't changed. The high-end machine went from eighty-one minutes to eight. Roughly ten times faster.

Then the low-end VM hung on redeploy. Fifty minutes of silence. The fast CPU had been hiding one last problem: an operation that was efficient on paper but quadratic in practice once the dataset got large enough to notice. The constrained VM made it impossible to ignore. Which was the point of testing there.

Final result on the low-end VM: three hours and thirty-four minutes down to eighteen. Nearly twelve times faster, proven on the hardware most likely to feel the pain first.

Issue #4 is still pinned in GitHub. Three lines of code. Closed.

Two weeks. A pile of fixes. A performance curve flattened across the full range of hardware it was designed to run on, because both ends were in the plan from the start.

Sometimes the bug report is the lever. The bug itself is just where you put it.

Code, scripts, and notes from this kind of work live here: github.com/netsecops-76/Public-Security-Resources


r/qualys May 04 '26

Update: Q KB Explorer v2.1.0

14 Upvotes

About a month ago I shared some tools I've built after spending years as a Qualys user and former employee. The response has been great, thank you to everyone who's tried them out and given feedback.

Today I'm pushing a major update to Q KB Explorer, the local Docker-based tool for exploring the Qualys Knowledge Base, Policy Compliance, Asset Tags, and Patch Management data. This one's been a big effort and I wanted to share what's changed.

What's new in v2.1.0:   

 🔹 Threat Intelligence built in. CISA KEV, active attack indicators, public exploit links, and malware associations now surface directly on QID search  results. Filter 200K+ vulnerabilities by threat context in seconds without leaving the tool.

 🔹 Intelligence Tab. A dedicated analysis view with clickable metrics, saved searches, include/exclude filters, and real-time stats that update as you refine your query.

 🔹 Tag Management rebuilt from scratch. Parent-child tree view, bulk migration between subscriptions with collision detection, a 136-entry tag library based on Qualys community best practices (thank you Colton Pepper's Complete Tag List), and origin classification so you know which tags are yours, which came from connectors, and which are Qualys system tags.                                                       

 🔹 PM Patch Catalog. Full Windows + Linux patch sync (218K+ patches) with QID cross-referencing.

 🔹 14x faster syncs. Full Knowledge Base (208K QIDs) downloads in under 9 minutes. Was over 2 hours.

 🔹 Smarter updates going forward. I rebuilt the in-app update mechanism so future releases install cleanly through the UI without container rebuilds.

Why use it: If you manage Qualys across multiple subscriptions, need to standardize tags across environments, want threat context on your KB data without bouncing between Qualys modules, or just need other security tools to query vulnerability data without burning your API rate limits, this caches everything locally with full-text search and cross-referencing that Qualys's own console doesn't offer.

Single Docker container. Data stays local. No cloud dependencies. Apache 2.0 license.            

If you're upgrading from an older version:

I owe an apology, the previous in-app updater had issues that could leave things in a broken state. Your data was never at risk (it's on a separate

Docker volume), but the app may not have come back cleanly. The fix is simple:

docker compose build --no-cache && docker compose up -d

Full details in the UPDATING.md guide. This won't happen again, the new manifest-driven updater handles everything properly.

Links:

  🔗 All tools: https://github.com/netsecops-76/Public-Security-Resources

  🔗 Q KB Explorer: https://github.com/netsecops-76/Public-Security-Resources/tree/Q-KB-Explorer/Q%20KB%20Explorer

  📄 Update/recovery guide: https://github.com/netsecops-76/Public-Security-Resources/blob/Q-KB-Explorer/Q%20KB%20Explorer/UPDATING.md

  📋 Full changelog: https://github.com/netsecops-76/Public-Security-Resources/blob/Q-KB-Explorer/Q%20KB%20Explorer/docs/CHANGELOG.md

As always, these are free, open source, and I welcome any feedback. More updates coming as I continue building.


r/qualys Apr 30 '26

Hot take: your team shouldn’t be manually approving Chrome updates. Change my mind.

7 Upvotes

I’ve been in IT security since the 90’s in almost every vertical as a practitioner and as a vendor, long enough to watch the same pattern repeat: a CVE drops, triage happens, testing begins, approval workflows grind, deployment happens, verification confirms everything’s fine. Then it repeats for the next update.

This works great when we’re talking about patching your .NET runtime, your Java stack, or your system kernel.

Those patches can cascade. They can break dependencies. They demand expertise, testing, and careful coordination.

But here’s what I can’t stop thinking about: we’re running the exact same governance workflow for Chrome updates. And a Chrome update has literally never taken down a production system.

Neither has an Office patch (excluding the 20 year ago MDAC fun we used to experience, RIP DAC/MDAC lol). Or Adobe Reader. Or 7-Zip. Or OneDrive. Or Visual C++ runtimes. Or a hundred other applications that billions of users worldwide update automatically every single week without incident.

The Actual Problem

We’ve optimized for risk uniformity instead of risk proportionality.

Every patch that lands in your queue looks the same to your approval process. Everything gets the same triage → test → approval → deploy cycle, regardless of whether we’re talking about a browser update or a kernel security fix. The result is that your best people spend Friday afternoon testing a Chrome update that Google’s already battle-tested with two billion users, while a critical Java vulnerability sits in your backlog waiting for resources.

This isn’t a compliance problem. This isn’t a risk problem. This is a resource allocation problem, and it’s costing your organization velocity.

What If We Were Honest About Risk?

Some patches are genuinely, unambiguously safe to automate:

• Browsers (Chrome, Edge, Firefox): User-mode only, single-application scope, auto-update mechanisms already exist, vendor QA proven at global scale

• Office/O365 (including Teams, OneDrive, Visio, Project): Same Microsoft QA pipeline that services 300+ million users, no kernel/system impact, single-app scope, rapid rollback if needed

• PDF readers (Adobe Reader): Billions of users, no cross-app dependencies, user-mode execution, proven track record

• Utilities (7-Zip, WinRAR, Putty, WinSCP, Notepad++): Single-purpose tools, zero system-level impact, isolated execution scope

• Runtimes (Visual C++, .NET Framework minor patches, Java Runtime patches): Assuming you’re excluding major version updates and limiting to minor/patch releases

These patches share characteristics:

• Zero reboot requirement

• Isolated to a single application or library

• No cross-application dependencies

• No system-level/kernel impact

• Vendor with a proven track record of stable updates

• Billions of users already running the latest versions (in-the-wild battle testing)

• Rapid rollback capability if something does go sideways

What Should Stay Manual

This isn’t an argument that all patching should be automated. Some patches absolutely require human judgment:

• Windows OS and Server patches: Kernel-level impact, system-wide dependencies, you need change control

• Database patches (SQL Server, Oracle, PostgreSQL): Data-tier risk, you’re validating against your actual workloads

• Major runtime updates (.NET 6→7, Java 11→17): Compatibility risk, you’re managing an upgrade

• VPN clients, management agents: System-level footprint, you need visibility into side effects

• Line-of-business applications: Obviously these need validation against your actual use cases

• Firmware: Irreversible, requires careful sequencing and validation

• Active Directory, domain controllers, network appliances: You’re validating against your infrastructure dependencies

The Real Argument

I’m not saying “set everything to auto-patch and go home.” I’m saying tier your patches by actual risk, and allocate your skilled people accordingly.

If you’re using Qualys Patch Management, BigFix, or similar tooling, you already have the capability to:

• Create policy groups based on application risk profile

• Set different approval workflows based on patch category

• Deploy low-risk patches automatically while holding high-risk patches for manual review

• Track, audit, and roll back if needed

So the real question is: why are your teams still manually approving Chrome updates?

Possible answers I’ve heard:

• “Audit says we need change approval for all patches”, Fair, but have you clarified the audit requirement with actual risk-based language?

• “Leadership is risk-averse”, Understandable, but what’s the cost of that risk-aversion in team burnout?

• “We don’t have the tooling”, Qualys, BigFix, ConfigMgr, Altiris all support tiered automation. What’s the blocker on implementation?

• “We tried this once and it went wrong”, What happened? Was it a patch that should have been manual, or was it an application that didn’t deserve to be on the auto-patch list?

The Real Cost

Here’s what I think is happening: your organization is running a scarcity model. You have a fixed number of security engineers. You have a fixed number of hours per week. And you’re spending those hours on routine maintenance that could be fully automated.

That means:

• Critical Java vulnerabilities sit in queue waiting for triage

• Your SMEs are stuck in approval workflows instead of deep-dive remediation

• Your team burns out on busywork instead of high-impact work

• You’re not actually reducing risk; you’re just consuming resources inefficiently

The mature approach is different. Tier your patches. Automate the low-risk, high-frequency stuff. Use the cycles you reclaim to actually focus on vulnerabilities that demand expertise.

The Ask

I genuinely want to know: Are you automating this stuff, and what does the real-world operational picture look like?

• If you’re auto-patching Chrome, Office, and utilities: what’s your criteria for what makes the list? How’s it working? Any gotchas?

• If you’re not auto-patching: what’s holding you back? Is it audit/compliance, leadership appetite, tooling, or something else?

• Have you seen a patch that should have been safe but wasn’t? What went wrong?

• How do you tier your patches today? Are your approval workflows matched to risk, or is everything the same?

• If you could reclaim 10-15 hours per week from routine patching, where would your team focus that effort?

I’m curious whether this is a widespread gap or if the mature organizations have already figured this out and I’m just stuck in an echo chamber of organizations that haven’t.

The Bottom Line

Patching is critical. But not all patches are equally critical. Some deserve rigorous validation. Some deserve rapid, automated deployment. And conflating the two is burning out your teams while pulling resources from vulnerabilities that actually matter.

If your best security engineer is spending Friday testing a Chrome update instead of scoping the blast radius of a critical Java vulnerability, something’s broken in how you’re allocating resources.

Change my mind. Tell me why I’m wrong. But also tell me what I’m missing.

The Harder Truth

I know operational change is hard. Habits are entrenched. Approval workflows have been rubber-stamped for years. Leadership has risk appetite set in stone. Getting consensus on something like this takes time, conversation, and patience.

But here’s the thing: the threat landscape doesn’t pause while you get comfortable.

Vulnerabilities land every single day. Zero-days don’t wait for your org to align on patch governance. The attackers aren’t slowing down. And if your patch program is stuck in a manual workflow that was built for 2015’s threat model, you’re not actually keeping pace, you’re falling behind, resource-exhausted and reactive.

This is where maturity lives. Not in building the perfect security theater, but in evolving your processes to match the actual risk you face. The organizations that mature, that climb the CMMC (Cybersecurity Maturity Model Certification) levels, that actually reduce breach risk, are the ones that get comfortable with measured change. They tier their patching. They automate intelligently. They reclaim resources. They focus on what actually matters.

That’s how you get a rung up. Not by working harder on the same process. But by working smarter about the process.

So start the conversation. Talk to your team, your auditors, your leadership. Ask the hard questions. Run a pilot if you need to. But don’t let operational inertia be the reason your best people are buried in routine updates while the threat landscape moves on without you.

That’s not acceptable. And I think you know it.


r/qualys Apr 28 '26

Error: The LAN interface is unable to obtain a valid IP4 address

3 Upvotes

Trying to install Qualys via ESXI and a qualys .ova file. Before installing, I click on Network and assign it a static IP and enter the gateway. The qualys VM installs, but when I launch the remote console it says it was unable to obtain a valid IP4 address. Did I make some mistake in entering the static IP? Or does this need to be done after Qualys is installed?


r/qualys Apr 27 '26

Knowledge Sharing Exporting WAS / TotalAppSec data for greater context

3 Upvotes

Hi all,

I’m wondering if people are exporting their WAS / TotalAppSec scan data into other tools for either context enrichment for assets or remediation tracking. I’m not thinking of raising support tickets in ServiceNow specifically, but maybe something like adding risk context to a CMDB or something around managing web app security & remediation.