Qualys has launched InstaScan, a new capability within its Enterprise TruRisk Management (ETM) platform designed to identify exposures within minutes of public vulnerability disclosure.
The company said InstaScan is powered by “Agent Insta”, which monitors newly published vendor security advisories and threat intelligence from Qualys and third-party sources, then correlates them with an organisation’s asset inventory and telemetry to identify affected systems.
The announcement comes as organisations face rising vulnerability volumes and faster exploitation timelines. Qualys cited data that 46,048 CVEs were published in the first seven months of 2026, nearly matching the total for all of 2025. It also referenced Verizon’s 2026 Data Breach Investigations Report, which said vulnerability exploitation was the leading breach entry point, accounting for 31% of breaches.
“Qualys InstaScan moves threat intelligence from telling you what already happened to detect exposure the moment it emerges; that’s true proactive detection,” said Theresa Lanowitz, principal cybersecurity analyst at Omdia.
Qualys said InstaScan introduces “scanless scanning”, shifting detection triggers from periodic scan windows to new advisory publication and asset changes. Across its initial set of supported technologies, the company said InstaScan covers 90% of detections within minutes.
“The speed of vulnerability exploitation has fundamentally changed,” said Sumedh Thakar, president and CEO of Qualys. “A slow vulnerability management program is now the biggest vulnerability an organisation has.”
Qualys said InstaScan is available within ETM and is intended to feed detections into prioritisation, validation and remediation workflows on the company’s platform.

