Company says, Qualys InstaScan is the intelligence layer that powers continuous vulnerability detection across the Qualys platform.
Qualys has announced InstaScan, powered by Agent Insta, a new capability in Qualys Enterprise TruRisk Management (ETM) that uses existing asset telemetry to provide continuous visibility into vulnerabilities after they are disclosed.
In the first seven months of 2026, 46,048 CVEs were published, nearly matching the total for all of 2025. Verizon’s 2026 DBIR also identified vulnerability exploitation as the leading breach entry point, accounting for 31% of breaches, and found that AI is shortening attacker timelines from months to hours.
Qualys research found that among KEV-linked vulnerabilities that were eventually remediated, the median time from detection to closure was nine days, while the KEV-linked workload increased 78% year over year.
“Qualys InstaScan moves threat intelligence from telling you what already happened to detect exposure the moment it emerges; that’s true proactive detection,” said Theresa Lanowitz, Principal Cybersecurity Analyst, Omdia. “As threat intelligence becomes a core variable in how organizations quantify risk, InstaScan gives Qualys a direct way to feed that signal into the platform.”
According to Qualys, InstaScan introduces “scanless scanning” within Qualys ETM. Powered by Agent Insta, it continuously monitors new vendor security advisories and threat intelligence, then matches emerging vulnerabilities against an organization’s asset inventory and telemetry. It automatically identifies affected assets and provides detections within minutes
Across its initial set of supported technologies, InstaScan covers 90 percent of detections within minutes, claims Qualys.
According to Qualys InstaScan powered by Agent Insta helps to:
- Detect at the speed of disclosure — New vulnerabilities become visible within minutes of advisory publication, closing the exposure window before exploitation.
- Outpace the AI-accelerated threat landscape — Detection is triggered by new advisories and asset changes rather than fixed scan schedules. It keeps exposure data continuously current and enables the remediation process.
- Power autonomous defense — AI-normalized and confidence-scored detections provide signals that can be used to prioritize, validate and remediate vulnerabilities, helping reduce risk faster after a vulnerability is disclosed
“The speed of vulnerability exploitation has fundamentally changed,” said Sumedh Thakar, President and CEO of Qualys. “A slow vulnerability management program is now the biggest vulnerability an organization has. We’re entering a new era of vulnerability, one where detection is continuous – driven by live intelligence instead of scan cycles. Built on the Qualys platform, InstaScan helps organizations identify and reduce risk the moment new vulnerabilities are disclosed.”
Availability
InstaScan is now available within Qualys ETM.
Disclaimer: This article is based on the official product launch announcement by Qualys. It has been edited for length and readability. Product claims, technical specifications and availability are provided by the manufacturer.
