Enterprise TruRisk Management Release 1.11

July 06, 2026

Enhanced Visibility with Status-Based Breakdown in Scan Results

The Exploitation Validated column on the Scan tab now provides a detailed, status-based breakdown of TruConfirm findings, enhancing visibility into scan results. Along with the count of validated exploits, it also displays validation outcomes across multiple statuses. You can see the scan results in the following format:

  • Inconclusive – 1
  • Ruled Out – 1
  • Validated – 0

The status breakdown is provided in detail

Scan Pause, Resume, and Delete for TruConfirm Scans

You can now pause, resume, and delete TruConfirm scans from the Scan tab. These actions are available for individual scans and for multiple scans in bulk. The following scan statuses have been introduced to indicate the current state of a scan:

  • Pausing: Indicates that a running scan is in the process of being paused.
  • Paused: Indicates that a scan has been paused. You can resume scans in this state.
  • Resuming: Indicates that a paused scan is in the process of resuming. Once the resume operation completes, the scan enters the Running state.

A scan can be deleted by the user who created it or by any user with the appropriate delete permissions.

Pause, Resume, and Delete options are added

DNS-based Scans for TruConfirm

You can now launch scans using FQDNs/DNS URLs in addition to IPv4 and IPv6 addresses and ranges. This enhancement allows you to target assets based on their FQDNs or DNS URLs when configuring scans.

Now users can use FDNs to launch the scans

Default Option Profile for TruConfirm Scans

When you launch a TruConfirm scan from the Scan tab or the Risk Management tab, the Option Profile field in Step 1: Basic Information now displays a pre-selected default option profile.

Now by default the option profile is pre selected

ETM Integration with TruRisk Eliminate

Risk Workbench Prioritization is now integrated with TruRisk Eliminate, enabling organizations to move seamlessly from vulnerability prioritization to remediation within a single workflow.

This integration allows security and operations teams to:

  • Link Prioritization Plans with Elimination Plans.
  • Assign remediation ownership.
  • Track remediation progress and plan performance.
  • View available patches and remediation options.
  • Monitor risk reduction through enhanced impact analysis and trend reporting.

The availability of Elimination-specific capabilities depends on TruRisk Eliminate licensing and subscription.

The following image highlights the new Prioritization plan window, where you can view new plan status, an option to view Detailed View, Impact, and a new column that states Elimination Options.

New Prioritization plan window.

The risk reduction view is now updated with a more comprehensive impact section that highlights the following features.

Enhancement 
 
Description 

Static Plan Scope

The scope of a Prioritization Plan is now locked at the time of creation.

  • Assets and findings included during plan creation remain fixed.

  • Newly discovered assets or findings matching the same tags are not automatically added to the plan.

This enables accurate progress tracking and reporting throughout the lifecycle of the plan.

Remediation Owner Column

 

You can now assign a Remediation Owner when handing off a plan to operations teams, providing clear accountability for remediation activities.

Plan Progress Column 

A new Plan Progress column displays the percentage of findings remediated through TruRisk Eliminate.

Enhanced Impacted  Findings 

A redesigned Impact section provides a consolidated view of Critical Assets, Critical Findings, and Available Patches.

Remediation Insights

View remediation and patch information for prioritized findings to identify available actions and monitor remediation activities.

Performance Trending

Monitor remediation performance over time with trend reports for open findings, fixed findings, and remediation progress.

Prioritization Plan Details 

The Plan Details page now includes key impact information, including affected critical assets, critical findings, and available patches within the selected scope.

Findings Listing

The Findings table displays available remediation and patch options for eligible findings.

Elimination View

A dedicated Elimination view provides visibility into remediation activities, including available and applied remediation, associated CVEs, and remediation status

CVSS v4 Support Fields Support

This release introduces support for CVSS v4 metrics and attributes across multiple Qualys platform components, enabling you to leverage the latest vulnerability scoring standard for analysis, reporting, search, grouping, alerting, and integrations.

The following CVSS v4 attributes are now supported:

  • CVSS v4 Base Score
  • CVSS v4 Temporal Score
  • CVSS v4 Rating (Low, Medium, High, Critical)

Vulnerability Listing Enhancements 

CVSS v4 data is now available in:

  • Vulnerability listing pages
  • Risk Workbench
  • Finding Details page
  • CVE Details page
  • Group By functionality
  • Search functionality
  • Column selection
  • Custom Attributes

You can now:

  • Search vulnerabilities using CVSS v4 attributes

    Search vulnerabilities using CVSS v4

  • Group findings by CVSS v4 attributes using Group by option

    Group findings by CVSS v4 attributes

  • Filter results using CVSS v4 scoring criteria

The following table describes the enhancements available for CVSS v4  

Enhancement 
 
Description 

Vulnerability Listing Enhancements

CVSS v4 data is now available in:

  • Vulnerability listing pages

  • Finding Details page

  • Group By functionality

  • Search functionality

  • Column selection

Search and Group By Support

You can now:

  • Search vulnerabilities using CVSS v4 fields

  • Group findings by CVSS v4 attributes

  • Filter results using CVSS v4 scoring criteria

Alerting Enhancements

Alerting now supports new CVSS v4 tokens:

  • CVSS v4 Base Score

  • CVSS v4 Temporal Score

These tokens can be used while configuring alerting workflows and notifications.

Risk Management Support

CVSS v4 fields are now supported in:

  • Risk Acceptance

  • Risk Factors

  • Compensating Factors

Custom Attributes

CVSS v4 information is available via custom attribute support, enabling customers to consume and use it for reporting and automation.

Public API Support

CVSS v4 fields are exposed through Public APIs, allowing external systems and integrations to access CVSS v4 scoring information

Scoring Display Logic

The CVSS Score column follows a priority-based display mechanism:

  • CVSS v4 Score

  • CVSS v3 Score

  • CVSS v2 Score

If CVSS v4 data is unavailable for a finding, the system automatically displays the next available version score.

Dashboard and Asset Details Support

CVSS v4 tokens are supported in:

  • Dashboard widgets

  • Asset details pages

  • Vulnerability-related views

New Tokens to Support CVSS v4 

We added new tokens to help you refine your findings based on CVSS v4.

Token

Tab

Description

finding.cvss4BaseScore

  • Risk Management > all Findings tabs 
  • DashboardQuery Settings > Findings

Provide a numeric value (0.0 to 10.0) to find vulnerabilities with a specific CVSS 4.0 Base score.

finding.cvss4BaseScore: 7.5

finding.cvss4Criticality

  • Risk Management > all Findings tabs 
  • DashboardQuery Settings > Findings

Use this token to search vulnerabilities based on CVSS v4 criticality. Select a criticality HIGH, MEDIUM, or LOW from drop-down menu.

finding.cvss4Criticality: MEDIUM

finding.cvss4TemporalScore

  • Risk Management > all Findings tabs 
  • DashboardQuery Settings > Findings

Provide a numeric value (0.0 to 10.0) to find vulnerabilities with a specific CVSS 4.0 Temporal score.

finding.cvss4TemporalScore: 6.5

Finding Count Breakdown by QVSS Range in ETM Tag Widgets

This enhancement introduces a QVSS-based breakdown of finding counts (Critical, High, Medium, Low) in the Tag Hierarchy Widget of ETM dashboards.

Configurable Tag Selection Limit

You can now select multiple tags from the tag dropdown. By default, you can select up to 5 tags. The maximum tag selection limit is configurable. To increase this limit, contact Qualys support.

Dynamic Table Column Selection

A new option is added to allow you to customize the columns displayed in the table. You can select the columns to display option. Only the selected columns are displayed in the table. This improves usability by displaying only relevant information.

The feature enables you to:

  • View granular risk distribution per tag
  • Prioritize findings based on severity categories
  • Improve decision-making and remediation prioritization

Key enhancements include:

  • New columns introduced in the Tag Hierarchy Widget:
    • Critical Findings
    • High Findings
    • Medium Findings
    • Low Findings
  • These represent counts grouped by QVSS score ranges.

To add the widget to your dashboard, navigate to Dashboard, click Add Widget, and then add Build your Widget. You can view the option in Query Settings > Tags.

View  Tag Hierarchy Widget.

Issues Addressed

The following reported issues are fixed in this release.

Component Description
Dashboard   The user could not select all Business Entities while creating the Explore Business Entities Insights Widget because the system limited the list to fewer items. This was caused by a limit setting in the API/UI. The issue is now fixed, and more entities can be fetched and selected correctly.  
Dashboard   Some Business Entities were not visible in the dashboard filters even though they existed. This happened due to a display limit on the UI. The issue is now fixed, and all entities are correctly shown and selectable. 
HomePage  Users experienced slow loading (more than 1 minute) when navigating from VMDR to ETM. This was caused by a cache check. The issue is resolved, and the page now loads faster. 
Dashboard  Dashboard Venn Type widgets showed no data when one of the QQL queries had no data, even if other queries had valid data. This was due to incorrect handling of mixed query results. The issue is resolved, and widgets now show available data correctly.
HomePage  Users could see Business Entities and vulnerabilities outside their assigned scope. This happened because scope restrictions were not applied properly. The issue is fixed, and users now only see data within their permitted scope. 
Custom Attributes Group by Sensors Activated Modules showed no data because the required support was missing. The issue is now fixed, and grouping works correctly with proper data display.
Findings  Vulnerabilities marked as fixed in VMDR were still shown as active in ETM due to a sync issue between systems. The issue is resolved, and the vulnerability status now reflects correctly in ETM.
Dashboard  Dashboard widgets had limited Group By options, restricting reporting flexibility. The issue is resolved, and more grouping fields are now available for better reporting.