EU03, AU01 and CA01 Platforms: False-Positive Vulnerability Findings with Cloud Agent for Windows 6.5 / 6.6 (IM-12827)

Incident Report for Qualys, Inc.

Resolved

This incident has been resolved. The affected version was rolled out only to the EU03, AU01, and CA01 platforms, and the published agent version on these platforms has already been reverted to 6.4 to prevent further agents from auto-upgrading. A fix has already been identified and will be delivered in Cloud Agent for Windows 6.7.2, starting rollout on August 24, 2026.
Posted Aug 19, 2026 - 15:52 PDT

Identified

Qualys Cloud Operations has observed an issue with Cloud Agent for Windows versions 6.5 and 6.6 that may cause certain vulnerability detections to be reported as false positives. Only QIDs whose detection logic reads a file from disk and evaluates its file version may be impacted. This is a reporting issue only and does not indicate any change to the actual security posture of affected hosts.

The incident ticket for reference is IM-12827.
Posted Aug 19, 2026 - 15:47 PDT
This incident affected: CA Platform 1 (Cloud Agent (CA)), AU Platform 1 (Cloud Agent (CA)), and EU Platform 3 (Cloud Agent (CA)).