Qualys Launches InstaScan to Detect New Vulnerabilities Within Minutes

Qualys launched InstaScan, a new capability in Qualys Enterprise TruRisk Management that uses asset telemetry, vendor advisories and threat intelligence to identify vulnerabilities within minutes of disclosure.

The company described the approach as scanless scanning. Instead of waiting for a scheduled scan window, InstaScan correlates emerging vulnerabilities with live inventory, exposure data and threat telemetry already collected by the Qualys platform.

Disclosure Timelines Are Compressing

Qualys said 46,048 CVEs were published in the first seven months of 2026, nearly matching the total for all of 2025. The company also cited faster attacker timelines as AI changes how quickly new vulnerabilities can be operationalized.

That environment makes traditional scan cycles harder to defend. If attackers can move from disclosure to exploitation in hours, a vulnerability management program that waits days for detection starts with a visibility disadvantage.

Telemetry Becomes The Detection Layer

InstaScan is powered by Agent Insta, a cyber risk agent that monitors newly published advisories and threat intelligence, then correlates those signals with an organization’s inventory. Qualys said the system covers 90 percent of detections within minutes across its initial supported technologies.

For security teams, the practical benefit is faster prioritization. A trusted detection signal can feed remediation workflows, validation steps and risk scoring before a conventional scan cycle would have completed.

The Bottom Line

Qualys InstaScan is part of the broader move toward continuous exposure management. The useful test for enterprises will be whether scanless vulnerability detection reduces response time while keeping confidence high enough for automated remediation decisions.