TotalCloud Release 2.26

July 20, 2026

Qualys TotalCloud 2.26.0 raises the bar for multi-cloud security - delivering unified visibility, identity-aware risk intelligence, and broader cloud coverage across AWS, Azure, GCP, and OCI. This release is built for security teams who need to move faster, see further, and govern smarter across an ever-expanding cloud estate.

Multi-Cloud Inventory Overview

Applicable for:  aws azure gcp oci

The Multi-Cloud Inventory enhances the existing inventory experience by providing a consolidated view of resources across all connected cloud providers. The enhanced Cloud Inventory Overview page aggregates inventory data from Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (GCP), and Oracle Cloud Infrastructure (OCI), giving you unified visibility into your multi-cloud environment.

Benefits

  • Single Pane of Glass: Provides consolidated inventory visibility across multiple cloud environments from a single dashboard.
  • Improved Posture Visibility: View resource counts alongside posture status to quickly identify regions, accounts, and services requiring attention.
  • Faster Investigation: Navigate directly from inventory statistics to detailed inventory and posture records through clickable metrics.
  • Unified Data Model: The multi-cloud inventory architecture provides consistent reporting across cloud providers, simplifying inventory management and reporting.

The enhanced dashboard offers a centralized overview of inventory data across supported cloud providers. Each provider is shown through a dedicated summary card that displays:

  • Total number of cloud connectors
  • Total resources discovered
  • Total posture issues (failed controls)

unified_inventory

Additionally, you also get a unified resource view when you navigate to Inventory > Cloud > All.

cloud_all

Sensitive Data Scanning for GCP

Applicable for: gcp 

Qualys TotalCloud now extends sensitive data detection capabilities to Google Cloud Platform (GCP) instances. This enhancement enables security teams to identify exposed sensitive data, such as credentials, API keys, and tokens, across multi-cloud environments from a single, unified platform.

Key Features and Benefits

  • Secrets visible in TotalCloud Inventory: Detected secrets surface within the TotalCloud module under Security > Sensitive Data on individual instance detail pages. 

Prerequisites

  • GCP connector configured within Qualys TotalCloud.
  • Target instances must be Linux-based. Currently, Windows instances are not supported.
  • Zero-Touch Snapshot-Based Scan for GCP must be configured.

Navigate to TotalCloud > Inventory > [Select a GCP Instance] > Security > Sensitive Data tab to view secret detection findings for GCP.

sensitive_data

TruRisk™ Insights Catalog

Applicable for:  aws azure gcp

The TruRisk™ Insights Catalog gives you complete visibility into all available TotalCloud Insights, not just the ones currently detected in your environment. This helps you better understand the full range of risks TotalCloud can identify, along with clear descriptions and supporting details for each insight.

Benefits

  • Improved visibility into the complete TotalCloud Insights library
  • Better understanding of how insights are defined and triggered
  • Explore insights proactively to strengthen your security posture
  • Easy access to insight details and remediation guidance

Key Features

  • Explore All Insights in One Place:
    Browse a complete, searchable catalog of all TotalCloud Insights, including details such as source, cloud coverage, and categories, to easily find and understand relevant risks. Navigate to TotalCloud > Insights > Catalog to explore all insights.
    insights_catalogue
  • Understand Each Insight in Detail:
    Select any insight to view a comprehensive summary, including its description, contributing factors, and supported environments, giving you full clarity on what the insight represents.
    insights_catalogue_summary
  • Act with Confidence using Remediation Guidance:
    The Manual Remediation tab provides step-by-step manual remediation recommendations, so you know how to respond when an insight is triggered in your environment.
    insights_catalogue_remediation

Investigate Cloud Configurations

Applicable for:  aws azure 

Qualys TotalCloud introduces a new capability that enables you to investigate cloud environments through a metadata-driven query interface. This allows you to search and analyze resources using details such as properties, tags, identities, networking configurations, and compliance-related attributes, all from a single place, without using scripts or command-line tools.

After you validate a query, you can convert it into a reusable custom control using JSON Query Language (JQL). This helps you continuously monitor your environment for specific conditions, rather than running the same investigation repeatedly.

Benefits:

  • Search and analyze cloud resources using metadata
  • Build and run queries without writing scripts
  • Convert queries into reusable controls for ongoing monitoring

Navigate to TotalCloud > Investigate > Cloud Configuration, then enter a JSON query to view the resources. 

cloud_configuration

This feature is currently available as a BETA release. Contact your Technical Account Manager (TAM) or Qualys Support to get access. 

Extended AWS, Azure, and OCI Inventory Coverage

Applicable for:  aws azure oci

We have expanded our cloud security coverage by adding support for additional AWS, Azure, and OCI resource types in Cloud Inventory, enabling discovery, inventory, and security posture assessment across a broader range of cloud services. 

The resources are as follows:

Platform Resource Type
AWS Amazon Open Search Domain
Direct Connect Connections
DMS Replication
Document DB Clusters
Document DB Snapshots
Elasticache replication group
IAM Password Policy
Identity Pool
KMS
Launch Configuration
MSK Clusters
RDS Cluster
RDS Cluster Snapshot
VPC Peering Connections
Azure API App
API App Deployment Slots
API Management Service API
App Service Environment
Azure Databricks Workspace
Function App Deployment Slots
Logic App Deployment Slots
Logic Apps
Machine Learning
Route Tables
SQL Managed Instance
Virtual Network Peering
Virtual Network Subnet
Web App Deployment Slots
Workspaces
OCI Autonomous Databases
Big Data Service Clusters
Block Volume
Block Volume Backups
Boot Volume
Container Registry
Data Flow Applications
DB Systems
File Storage Mount Targets
File System
Key
Secret

Comprehensive Findings for Azure Virtual Machines

Applicable for: azure

The Azure Virtual Machine Inventory page now features interactive summary cards that offer an instant view of key security and configuration categories. Clicking a card automatically filters the inventory to show the corresponding set of virtual machines.

Benefits

  • Gain at-a-glance visibility into your Azure VM inventory.
  • Quickly identify VMs without agents, exposed via public IPs, and vulnerable to threats and more.
  • Eliminate the need to manually create or enter QQL filters.

Available Summary Cards

  • Without Agents: Virtual machines that do not have the Qualys agent installed.
  • With Public IP: Virtual machines exposed through a public IP address.
  • Docker Hosts: Virtual machines identified as Docker hosts.
  • With Vulnerabilities: Virtual machines with detected vulnerabilities.
  • With Threats: Virtual machines with detected threats.
  • With Insights: Virtual machines with available security insights.

 Selecting a card automatically applies the associated filter to the inventory list.

VM Summary Cards

Enhanced Azure CIEM Entitlements

Applicable for: azure

TotalCloud now provides Cloud Infrastructure Entitlement Management (CIEM) entitlements for Azure resources. This feature helps you identify over-privileged identities, analyze permission usage patterns, and reduce identity-related security risks across your Azure environment.

To view entitlements, select a supported Azure resource and click Entitlements on the Inventory Details page.

You can view CIEM entitlements for the following Azure resource types:

  • User
  • Group
  • App Registration
  • Service Principal
  • Managed Identity
  • Virtual Machine (VM)

entitlement

 Tenant Connector configuration is required for this feature. If a Tenant Connector is not configured, the Azure CIEM Policy Analyzer will not be triggered, and policy analysis will not be performed.

Enhanced Alert Messages to include Connector context

Applicable for:  aws azure

Posture alert notifications now include connector metadata, providing additional cloud context to help you quickly identify the connector and cloud resources associated with an alert.

The following connector metadata is now included in alert notifications:

AWS: Account Alias and Resource Tag

Azure: Subscription Name and Resource Group

Azure Resource Tag Support

Applicable for: azure

You can now use Azure tokens across the Posture, Dashboard, Reports, Inventory and Alert Rules. This allows you to filter data on these tabs using the following tokens: azure.tag.key and azure.tag.value.

You can use these tokens on the following tabs:

  • Inventory and Posture: Filter resources by Azure tag key or value.
  • Dashboard: View data for resources with specific Azure tags.
  • Reports: Generate reports for resources with specific Azure tags.
  • Alert Rules: Create alerts for resources with specific Azure tags.

Vertex AI - Resource Name Updated

Applicable for: gcp

We’ve updated the GCP Vertex AI inventory name to align with Google Cloud’s latest branding. It is now called Gemini Enterprise Agent Platform.

New Tokens

The following section describes the new tokens introduced as part of TotalCloud 2.26.0

Inventory Tokens

Applicable for: azure

The following new tokens are added for resource types: User, Group, App Registration, Service Principal, Managed Identity, and Virtual Machine

Name Description Example
azure.iam.permission.subscriptionId Use this to find Azure IAM permissions by Azure subscription ID azure.iam.permission
.subscriptionId:
xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
azure.iam.permission.classification Use this to find Azure IAM permissions by entitlement classification. azure.iam.permission
.classification: Privileged

Control Updates

New AWS IaC Build-Time Controls

Applicable for: aws

Platform CID Title Service Type Resource Type Criticality Policy
AWS 723 Ensure Kendra index Server side encryption uses CMK KENDRA KENDRA INDEX Medium AWS Infrastructure as Code Security Best Practices Policy
AWS 724 Ensure AppFlow flow uses CMK APPFLOW APPFLOW FLOWS Medium AWS Infrastructure as Code Security Best Practices Policy
AWS 725 Ensure AppFlow connector profile uses CMK APPFLOW APPFLOW FLOWS Medium AWS Infrastructure as Code Security Best Practices Policy
AWS 726 Ensure Keyspaces Table uses CMK KEYSPACE KEYSPACE TABLE Medium AWS Infrastructure as Code Security Best Practices Policy
AWS 727 Ensure DB Snapshot copy uses CMK RDS RDS SNAPSHOT Medium AWS Infrastructure as Code Security Best Practices Policy
AWS 728 Ensure that Comprehend Entity Recognizer's model is encrypted by KMS using a customer managed Key (CMK) COMPREHEND COMPREHEND ENTITY RECOGNIZER MODEL Medium AWS Infrastructure as Code Security Best Practices Policy
AWS 729 Ensure that Comprehend Entity Recognizer's volume is encrypted by KMS using a customer managed Key (CMK) COMPREHEND COMPREHEND ENTITY RECOGNIZER MODEL Medium AWS Infrastructure as Code Security Best Practices Policy
AWS 730 Ensure Connect Instance Kinesis Video Stream Storage Config uses CMK CONNECT CONNECT Medium AWS Infrastructure as Code Security Best Practices Policy
AWS 731 Ensure Connect Instance S3 Storage Config uses CMK CONNECT CONNECT Medium AWS Infrastructure as Code Security Best Practices Policy
AWS 732 Ensure DynamoDB table replica KMS encryption uses CMK DYNAMO_DB DYNAMO DB TABLE Medium AWS Infrastructure as Code Security Best Practices Policy
AWS 733 Ensure AWS Lambda function is configured to validate code-signing LAMBDA LAMBDA High AWS Infrastructure as Code Security Best Practices Policy
AWS 734 Ensure access is controlled through SSO and not AWS IAM defined users IAM IAM USER High AWS Infrastructure as Code Security Best Practices Policy
AWS 735 Ensure aws_iam_role does not have managed_policy_arns set to the AWS AdministratorAccess policy IAM IAM ROLE High AWS Infrastructure as Code Security Best Practices Policy
AWS 736 Ensure aws_iam_policy_attachment does not have policy_arn set to the AWS AdministratorAccess policy IAM IAM POLICY High AWS Infrastructure as Code Security Best Practices Policy
AWS 737 Ensure aws_iam_group_policy
_attachment does not have policy_arn set to the AWS AdministratorAccess policy
IAM IAM GROUPS High AWS Infrastructure as Code Security Best Practices Policy
AWS 738 Ensure aws_ssoadmin_managed
_policy_attachment does not have managed_policy_arn set to the AWS AdministratorAccess policy
IAM IAM POLICY High AWS Infrastructure as Code Security Best Practices Policy
AWS 739 Ensure aws_iam_role_policy
_attachment does not have policy_arn set to the AWS AdministratorAccess policy
IAM IAM ROLE High AWS Infrastructure as Code Security Best Practices Policy
AWS 740 Disallow policies from using the AWS AdministratorAccess policy IAM IAM POLICY High AWS Infrastructure as Code Security Best Practices Policy

New AWS Controls (Available for Custom Policy Attachment)

Applicable for: aws

Platform CID Title Service Resource Criticality
AWS 700 Ensure Network Firewall policies have a user-defined stateless default action for fragmented packets VPC NETWORK FIREWALL
POLICY
Medium
AWS 701 Ensure Network Firewall policies have a stateless default action of drop or forward for full packets VPC NETWORK FIREWALL
POLICY
Medium
AWS 702 Ensure Stateless Network Firewall Rule Groups contain rules VPC NETWORK FIREWALL RULE GROUPS Medium
AWS 703 Ensure AWS VPC gateway endpoint policy does not contain wildcard(*) without a condition statement VPC VPC High
AWS 704 Ensure Relational Database Service (RDS) for PostgreSQL instances use SCRAM as the password encryption and authentication method RDS RDS High
AWS 705 Ensure no Virtual Private Cloud (VPC) Network Access Control List (NACL) allows all protocols VPC NETWORK ACL High
AWS 706 Ensure that VPC has an AWS KMS VPC endpoint configured VPC VPC High
AWS 707 Ensure that VPC has an AWS CloudWatch Logs VPC endpoint configured VPC VPC Medium
AWS 708 Ensure that VPC has an AWS CloudWatch Monitoring VPC endpoint configured VPC VPC Low
AWS 709 Ensure that VPC has an AWS Lambda VPC endpoint configured VPC VPC Medium
AWS 710 Ensure that VPC has an AWS API Gateway VPC endpoint configured VPC VPC Medium
AWS 711 Ensure that VPC has an AWS EC2 VPC endpoint configured VPC VPC Medium
AWS 712 Ensure that VPC has an AWS Secrets Manager VPC endpoint configured VPC VPC High
AWS 713 Ensure that VPC has an AWS CloudFormation VPC endpoint configured VPC VPC Medium
AWS 714 Ensure that VPC has an AWS S3 VPC endpoint configured VPC VPC High
AWS 715 Ensure no IAM user is configured with console login credentials and active access keys simultaneously IAM IAM USER Medium
AWS 716 Ensure Relational Database Service (RDS) MariaDB and MySQL instances enforces encryption in transit RDS RDS High
AWS 717 Ensure Relational Database Service (RDS) IBM Db2 instances enforces encryption in transit RDS RDS High
AWS 718 Ensure Auto Scaling group launch template should not have a metadata response hop limit greater than 1 EC2 LAUNCH TEMPLATE Medium
AWS 719 Ensure that VPC security groups do not allow unrestricted access on all ports VPC VPC High
AWS 720 Ensure AWS Network Firewall policy has Intrusion Prevention System (IPS) enabled via stateful rule groups with drop actions NETWORK FIREWALL NETWORK FIREWALL POLICY Medium
AWS 721 Ensure that all EIP addresses allocated to a VPC are only attached to NAT Gateways EC2 EC2 Medium
AWS 722 Ensure EC2 instances launched using Auto Scaling group launch Configurations must not have Public IP addresses EC2 LAUNCH CONFIGURATION Medium

New Controls for Azure (Available for Custom Policy Attachment)

Applicable for: azure

Platform CID Title Service Resource Criticality
Azure 50645 Ensure that Azure API Management APIs use only HTTPS or WSS protocols API MANAGEMENT SERVICES API MANAGEMENT SERVICES High
Azure 50646 Ensure that Azure Machine Learning Workspaces disable public network access MACHINE LEARNING MACHINE LEARNING High
Azure 50647 Ensure that Azure Database for MySQL flexible server does not allow 0.0.0.0 firewall rule AZURE MYSQL FLEXIBLE SERVER AZURE MYSQL FLEXIBLE SERVER High
Azure 50648 Ensure that Azure SQL Managed Instance has public data endpoint access disabled AZURE SQL SQL MANAGED INSTANCE High
Azure 50649 Ensure that Azure SQL servers must use private endpoints SQL SERVER SQL SERVER High
Azure 50650 Ensure that Azure Virtual Machine Scale Set instances do not have public IP addresses VIRTUAL MACHINE SCALE SETS VIRTUAL MACHINE SCALE SET High
Azure 50651 Ensure that Azure Service Bus namespace does not use insecure TLS version SERVICE BUS SERVICE BUS NAMESPACE Medium
Azure 50652 Ensure that Azure SQL Managed Instance does not use insecure TLS version AZURE SQL SQL MANAGED INSTANCE Medium
Azure 50653 Ensure that Azure Cosmos DB account does not use insecure TLS version COSMOS DB COSMOS DB Medium
Azure 50654 Ensure that Azure Application Gateway does not use insecure TLS version APPLICATION GATEWAYS APPLICATION GATEWAYS Medium

New controls for OCI

Applicable for: oci

Platform CID Title Service Resource Policy Criticality
OCI 40104 Ensure VCN flow logging is enabled for all subnets VCN SUBNET CIS Oracle Cloud Infrastructure Foundation Benchmark High
OCI 40103 Ensure OCI IAM credentials unused for 45 days or more are disabled IAM IAM USER CIS Oracle Cloud Infrastructure Foundation Benchmark High

Control Title Changes

Applicable for: aws

Platform CID Old Title New Title  
AWS 295 Ensure Cloudfront distribution ViewerProtocolPolicy is set to HTTPS Ensure Viewer Protocol Policy enforces HTTPS and Minimum TLS Version is set to TLS 1.2 or higher in CloudFront distributions
AWS 503 Ensure TLS 1.2 is configured for API Gateway custom domain Ensure TLS security policy is using 1.2 or higher version for the custom domains

Controls Deprecated

Applicable for: aws

Platform CID Description Control Type Policy Name Reason for Deprecation
AWS 400 Ensure an IAM User does not have access to the console BUILD RUN TIME AWS Identity Access Management Best Practices Policy
AWS Infrastructure as Code Security Best Practices Policy
New improved control (CID 715) has been introduced that covers the check of deprecated control.

Control Enhancements

Applicable for: aws azure

Platform CID Title Description
AWS 203 Ensure EBS Volume is encrypted by KMS using a customer managed Key (CMK) Fixed EBS volume evaluation logic to process all applicable volumes within an AWS account, ensuring accurate resource counts, complete assessment coverage, and reliable compliance reporting.
AWS 294 Ensure Customer managed KMS key policy does not contain wildcard (*) principal Enhanced AWS KMS key policy evaluation to correctly interpret Condition statements, improving compliance accuracy by distinguishing restricted wildcard principals from genuinely open policies.
AWS 295 Ensure Viewer Protocol Policy enforces HTTPS and Minimum TLS Version is set to TLS 1.2 or higher in CloudFront distributions Update Control Title and Predicate and also moved control from Get call to List call.
Enhanced CloudFront distribution evaluation by validating both DefaultCacheBehavior and additional CacheBehaviors, while also verifying MinimumProtocolVersion, improving assessment coverage and compliance accuracy.
AWS 503 Ensure TLS security policy is using 1.2 or higher version for the custom domains Updated control title and predicate logic.
Enhanced TLS version compliance evaluation by updating the predicate logic to recognize all supported compliant TLS versions instead of only TLS_1_2, ensuring more accurate compliance assessments.
Azure 50002 Ensure no SQL Servers allow ingress from Internet (ANY IP) Updated predicate logic to cover all the test cases related to publicNetworkAccess and also verify endIpAddress
Azure 50124 Ensure that Azure CosmosDB does not allow access from all networks Updated predicate logic to cover all the test cases related to publicNetworkAccess
Azure 50156 Ensure that public network access is disabled in Managed Disks Updated predicate logic to cover all the test cases related to publicNetworkAccess
Azure 50476 Ensure Allow public access from any Azure service within Azure to this server for PostgreSQL flexible server is disabled Updated predicate logic to cover all the test cases related to publicNetworkAccess

Issues Addressed

We fixed the following important and notable issue in this release.

Category/Component Issue
CV - EC2 Connector Resolved an issue where terminated AWS EC2 instances continued to appear as “Running” in the AssetView/Global AssetView UI. The issue occurred due to incorrect handling of connector ARN values (NULL ARN for CSA identifier), which caused failures during stale asset processing and prevented proper status updates. Users previously saw terminated assets incorrectly listed as active. The issue is now resolved and terminated EC2 instances are correctly marked in the UI.
Resolved an issue where users encountered a 500 Internal Server Error while merging connectors in the TotalCloud module. The issue occurred due to improper request handling during connector merge operations. Users previously could not merge connectors and received errors. The issue is now resolved and connector merge works correctly.
CV - Reports Resolved an issue where users encountered an error while creating CSPM reports when selecting the“last” option for monthly scheduling. The issue occurred due to incorrect recurrence handling logic. Users previously experienced report generation failures for this option while other options worked correctly. The issue is now resolved and report scheduling works correctly for all monthly recurrence options.
CV - API Resolved an issue in the API endpoint /evaluation/applyTags where applying tags using a regex pattern failed with“No resources/evaluations found” or NOT_FOUND errors. The issue occurred due to limitations in handling large datasets and failures during Elasticsearch query processing. Users previously could not apply tags using regex across multiple resources. The issue is now resolved and regex-based tagging works correctly as expected.
Addressed the use of a deprecated Azure Management API version (api-version=2014-04-01). The issue occurred due to outdated API usage in integration calls, which triggered Microsoft deprecation alerts. Users previously received warnings about potential impact. The issue is now resolved and supported API versions are used.
CV - False Positive Resolved a false positive issue where encrypted EBS volumes were incorrectly flagged as non-compliant for CID-203 (KMS encryption check). The issue occurred due to incorrect validation of encryption and KMS key details. Users previously saw compliant resources marked as failed. The issue is now resolved and compliance evaluation correctly reflects actual encryption status.