Qualys incident
EU03, AU01 and CA01 Platforms: False-Positive Vulnerability Findings with Cloud Agent for Windows 6.5 / 6.6 (IM-12827)
Qualys experienced a notice incident on August 19, 2026 affecting Cloud Agent (CA) and Cloud Agent (CA) and 1 more component, lasting 4m. The incident has been resolved; the full update timeline is below.
Affected components
Update timeline
- identified Aug 19, 2026, 10:47 PM UTC
Qualys Cloud Operations has observed an issue with Cloud Agent for Windows versions 6.5 and 6.6 that may cause certain vulnerability detections to be reported as false positives. Only QIDs whose detection logic reads a file from disk and evaluates its file version may be impacted. This is a reporting issue only and does not indicate any change to the actual security posture of affected hosts. The incident ticket for reference is IM-12827.
- resolved Aug 19, 2026, 10:52 PM UTC
This incident has been resolved. The affected version was rolled out only to the EU03, AU01, and CA01 platforms, and the published agent version on these platforms has already been reverted to 6.4 to prevent further agents from auto-upgrading. A fix has already been identified and will be delivered in Cloud Agent for Windows 6.7.2, starting rollout on August 24, 2026.