SwCA Scanner for Windows 1.24.8

October 07, 2026

SwCA Scanner for Windows 1.24.8 provides runtime support for Node.js, skips PHP and C++ language for runtime, fixes blank values in host-based reports, and prevents .NET language false-positive detection.

Enhancement

Enhanced Runtime Analysis: See Only What You Scan

What Changed For You

Enhanced Runtime analysis now shows what is scanned and reduces the false positives for unsupported language.

We have enhanced SwCA to support the Node.js language for runtime analysis. Also, runtime analysis now skips PHP and C++ language detections during runtime scans. This ensures that only vulnerabilities detected in the supported and scanned languages are reported during runtime analysis, reducing false positives.


- We have added the following new language support added for runtime analysis: Node.js
- The PHP and C++ languages are supported for only for the static analysis and skipped during the runtime analysis.

Fix

Fixes

The following important and notable customer issues are fixed in this release.

Component/Category Description
SwCA - Asset Details Issue: The DNS hostname, FQDN, and NetBIOS values for some assets were blank in host-based reports, but still appeared in the Qualys UI as SwCA scans did not collect the hostname and NetBIOS name.
Fix: SwCA scans now collect the same host information as VM scans, including the DNS hostname and NetBIOS name. These values stay populated after a SwCA scan, and reports return them correctly.
SwCA - False Positive Detection Issue: SwCA scans reported false-positive for .NET language because the .deps.json file could contain older version of an installed package.
Fix: The agent now reads and reports the package version on the runtime DLL, so updated packages are no longer flagged as vulnerable.