Initial Publication:August 4,2026EditAugust 5, 19:10 UTC: Impact section updated.EditAugust 6, 06:11 UTC: Formatting changes only.EditAugust 6, 06:35 UTC: Investigation concluded, removed banner.
Certainopen sourcepackages released by Qlik® have beenimpactedby an ongoing, industry-widenpmsupply chain compromise ("Shai-Hulud") affectingkeyv, cacheable, and related packages. As of this writing, the campaign has affected many organizations beyond Qlik, including over 440 unique packages and 2,200+ package versions across thenpmecosystem. A Qliknpmpublishing credential was harvested from an internal build system after it installed a package with a poisoned transitive dependency, and was used to publish unauthorized, malicious versions of several Qlik-ownedopen sourcepackages to the publicnpmregistry. Thisappears to bea consequence of the broader worm's automated spread across thenpmecosystem, rather than a targeted attack on Qlik. The investigation into full scope and impactremainsactive, and Qlik has taken active steps to mitigate the impact.
Impact
31 packages in the @qliknpmscope had malicious versions published to the registry, all published and detected within the same 10:46 to 10:53 UTC window on August 4, 2026:
Package
Version
@qlik/api
2.14.2
@qlik/browserslist-config
3.0.2
@qlik/carbon-core
2.1.1
@qlik/carboncopy
1.1.6
@qlik/design-tokens
1.3.13
@qlik/dts-bundler
2.0.3
@qlik/embed-react
2.5.3
@qlik/embed-runtime
1.6.4
@qlik/embed-svelte
1.1.4
@qlik/embed-web-components
1.7.3
@qlik/eslint-config
2.0.20
@qlik/eslint-config-base
0.1.1
@qlik/eslint-config-react
0.1.1
@qlik/eslint-config-svelte
0.1.1
@qlik/eslint-config-vue
0.1.1
@qlik/nebula-table-utils
2.6.9
@qlik/oxfmt-config
0.1.6
@qlik/oxlint-config
0.7.2
@qlik/prettier-config
1.0.3
@qlik/react-native-simple-grid
1.5.5
@qlik/runtime-module-loader
1.5.1
@qlik/sdk
0.28.1
@qlik/sprout-design-docs
1.0.2
@qlik/sprout-gesture
0.0.13
@qlik/sprout-icons
0.12.3
@qlik/sprout-react
6.45.3
@qlik/sprout-react-table
0.16.7
@qlik/tsconfig
1.0.3
qlik-chart-modules
1.1.1
qlik-modifiers
0.10.1
qlik-object-conversion
0.17.2
We have confirmed that no Qlik products, including Qlik Cloud, Talend Cloud, and our client-managed offerings, were impacted. No compromised code was released into any Qlik product.
What Qlik has done
Revoked the compromisednpmpublishing credential and disabled automated publishing pipelines (GitHub Actions), including across theqlik-ossorganization
Confirmed thatnpmremoved the malicious versions from the public registry; purging internal mirrors/caches
Added precautionary blocks on our cloud firewalls
Rotating exposed secrets and keys, in a controlled sequence, after confirming affected hosts are clean
Completed indicator-of-compromise sweeps across related GitHub organizations; no indicators of persistence found
Continuing a full investigation across our repositories and build infrastructure
What you should do
If you installed any of the affected package versions listed above:
Treat anynpm, GitHub, or cloud credentials present in that environment as potentially compromised
Scan for compromise before rotating credentials; do not rotate first
Reinstall using npm install --ignore-scripts once a clean version is confirmed available
More information
For independent tracking of the scale of this campaign across the npm ecosystem, see Socket's write-up: keyv and cacheable compromise.
...View More
Effective August 6th, 2026, the following breakdowns need to be enabled for Ad Accountsusing the Stitch Facebook Ads connector:
breakdowns=impression_device (and any combination including impression_device)
breakdowns=hourly_stats_aggregated_by_audience_time_zone
breakdowns=frequency_value
This change is driven by Facebook. For details, see Ads Insights API -- Breakdown Availability Changes | developers.facebook.com.
Thank you for choosing Qlik,Qlik Support
...View More
Qlik Cloud tenants hosted in the Europe (Ireland) region will undergo scheduled maintenance in August 2026 to upgrade the database supporting the underlying authentication service. The upgrade strengthens our ability to deliver a secure and reliable experience.
The maintenance window is expected to last 30 minutes.
Other regions are unaffected.
What is the expected impact?
If you are already signed in: You can continue working as usual.
If you need to sign out or sign in:Logging in and out are temporarily unavailable during the maintenance window. If you attempt to do so, you may encounter the following message:
{"errors":[{"title":"Unexpected server error","code":"UNEXPECTED","status":"500"}]}
This is expected and does not indicate a problem with your account.
What do I need to do to prepare?
No action is required.
What follow-up actions are required?
None.
When will the maintenance take place?
The maintenance is scheduled for:
Region
Maintenance Start
Maintenance End
Europe (Ireland)(eu-w-1)
Wednesday 12 August 202621:30 IST (Ireland)UTC: 12/08/26 – 20:30
Wednesday 12 August 202622:00 IST (Ireland)UTC: 12/08/26 – 21:00
To track further updates during the scheduled Qlik Cloud Maintenance, please visit our Qlik Cloud Status page. This blog post will be updated with additional information where necessary.
Thank you for choosing Qlik,Qlik Support
...View More
At the beginning of 2026, the Qlik Reporting Service expanded its offering with support for Microsoft Word and Microsoft PowerPoint report capabilities. For the duration of the first half of the year, these report formats have been executing in an unmetered state.
As of August 1st, 2026, these report formats will be metered. Customers using Word and PowerPoint reports will notice an increase in the report execution metrics.
What does this mean for me?
If you are a customer making use of these report formats, you should review your consumption and ensure that your Qlik Reporting Service quota is adequate for your aggregate report consumption at this time.
How do I know how many Word and PowerPoint reports are being sent?
Talk to your report developers, they would have a good understanding of which report task are in production and how many reports are being executed
For an aggregate view across your tenant, use the Report Analyzer appas perQlik Cloud Monitoring Apps Workflow Guide
Thank you for choosing Qlik,Qlik Support
...View More
Qlik Answers was built to do real analytical work: investigate root causes, reason across dimensions and time, and explain not just what happened but why. That depth is what our customers value most, and it isn't going anywhere.
But not every question needs an analyst. Sometimes you only need a number. What was the revenue last month? Top 10 products by margin? Open orders in EMEA right now? These are lookups, not investigations, and they deserve their own gear.
On the 7th of June 2026, Qlik added one: Fast Mode is now live in Qlik Answers, providing one assistant with the effort matched to the question. To read more about the release, see What's new in Qlik Cloud.
Fast Mode gives you near-instant answers to simple questions on your structured data, so quick checks feel as natural as glancing at a KPI. Thinking Mode remains your deep analyst for everything else, with all the reasoning power you rely on today.
Together, they work the way a great analyst does. Ask what sales were last month, and you get the number immediately. Ask why sales dropped in the North region, and the assistant rolls up its sleeves and does the work properly. Same assistant, same governed data, two gears.
Fast, and still your numbers
Plenty of AI tools can answer quickly. The question is whether you can trust what comes back.
Fast Mode is grounded in your app's governed semantics from the first query: master measures, master dimensions, your calendar logic, and your section access. When Fast Mode says "sales," it means sales exactly as your organization defines them, rather than AI math or a plausible-looking guess. You will get the same governed definitions your dashboards run on, at conversational speed.
And when a question deserves more than a fast answer, Fast Mode won't pretend otherwise. It tells you the question calls for deeper analysis and offers a one-click "Think harder" that hands the same question, full context intact, to Thinking Mode.
No need for rephrasing or starting over.
What each mode covers today
Fast Mode is currently available for structured data: questions answered from your apps, master measures, and master dimensions.
The rest of what makes Qlik Answers powerful stays with Thinking Mode. Questions over unstructured content like documents and knowledge bases, answers that blend structured and unstructured sources, and requests that trigger automations all need real reasoning, and Thinking Mode is built for exactly that.
That's a deliberate split: fast lookups where speed matters, full reasoning where the work demands it.
We know where the appetite goes from here, and we're watching how you use both modes closely. For now, if your question touches documents or kicks off an automation, Thinking Mode has you covered.
When to use which mode
A simple rule: if a colleague could answer from memory using your apps, use Fast Mode. If they'd need to open the app, read the documents, or take action, that's a job for Thinking Mode.
Fast Mode: "What was revenue last quarter?" "Top 5 regions by margin." "Open orders in EMEA right now?"
Thinking Mode: "Why did margin compress in Q2?" "What does our returns policy say, and how many orders does it affect?" "Flag these accounts and notify the owners."
Pick wrong? One click fixes it.
Try it today!Fast Mode is available now in Qlik Answers. Ask the question on your mind and see how fast a trusted answer can be. Then ask a hard one, hit "Think harder," and watch the assistant do what it does best.
Thank you for choosing Qlik,Qlik Support
...View More
Qlik Data Gateway - Direct Access version 1.6.x will be officially End of Life (EOL) on September 30, 2026.
Version 1.6 was initially released in December 2023 and reached End of Support on June 14, 2025. It is now confirmed for End of Life on September 30, 2026. Upgrade to a supported version as soon as possible.
How will this affect me?
Once version 1.6.x reaches End of Life, Direct Access Gateway instances still running 1.6.x after September 30 may lose connection to Qlik Cloud, disrupting data loads and any workloads that depend on it.
What should I do?
Upgrade to the latest available version of Qlik Data Gateway – Direct Access (currently 1.7.x, with 1.7.16 expected soon) before the End of Life date for 1.6.x. The new versions bring:• A redesigned gateway configuration UI, making setup and troubleshooting easier• Ongoing security fixes and cloud-side compatibility, which are not backported to older versions• Ongoing performance and reliability improvements
From version 1.6.6 onward, .NET 8.x is required. This is installed automatically as part of the upgrade process, so no manual action is required.
The upgrade path from 1.6.x to the latest 1.7.x release has been tested and is expected to run smoothly. As always, please review the upgrade steps carefully and take a backup before upgrading.
How do I upgrade?
Upgrading Qlik Data Gateway - Direct Access walks through the upgrade procedure and lists the significant changes introduced in each release.
Configuring and troubleshooting Qlik Data Gateway - Direct Access covers configuration options introduced in later versions that may apply to your deployment. Most gateway settings can also be managed directly in the Qlik Cloud Administration activity center (from v1.7.2).
What else should I keep in mind?
We recommend always running the latest available version of the Direct Access Gateway. Cloud-side fixes are deployed on a near-weekly basis, and these most often do not apply to older gateway versions — so staying current is the best way to avoid running into avoidable issues.
Questions?
If you have questions or need assistance planning your upgrade, our forums are open to you, and Support is only a chat away.
Thank you for choosing Qlik,Qlik Support
...View More
Effective September 1, 2026, Strava will deprecate three Club endpoints: Club Activities, Club Administrators, and Club Members. Strava has stated that the small number of developers using these endpoints does not support their continued maintenance.
As a result, the ClubActivities and ClubMembers tables in the Qlik Strava connector will no longer return data after this date and will be deprecated.
The following Qlik products and their related Strave connectors are affected:
Qlik Cloud
QlikView
Qlik Sense Enterprise on Windows
Why is this happening?
This change originates with Strava, not Qlik. Strava is deprecating these endpoints at the API level, so any application relying on them, including the Qlik Strava connector, is affected.
What action do I need to take?
Review your Qlik apps, scripts, and automations for any use of the ClubActivities or ClubMembers tables in the Strava connector. If you rely on this data, plan to remove or replace these data sources ahead of September 1, 2026, as they will stop returning data once Strava's deprecation takes effect.
No action is needed if you don't use these tables.
What happens if I don't act?
Any loads or automations using the ClubActivities or ClubMembers tables will stop returning data after September 1, 2026.
If you have any questions, we're happy to assist. Reply to this blog post or take your queries to our Support Chat.
Thank you for choosing Qlik, Qlik Support
...View More
Don't miss our previous Q&A with Qlik! Pull up a chair and chat with our panel of experts to help you get the most out of your Qlik experience.
Let our Qlik experts offer solutions and best practices for Qlik Cloud administration and answer your analytics questions.
WATCH HERE
...View More
Edited July 7th: Clarified that the change will begin rollout on July 28, 2026.
Qlik is introducing a change in which automation permissions are included in the Tenant Admin Automations scope.
When is the change being introduced?
The change is being rolled out beginning July 28, 2026.
What does that mean for me?
Anyone assigned the Tenant Admin Automations scope in a custom role will be able to claim ownership of another user's automation. After claiming ownership, they can make necessary changes to it and enable the automation. However, they can no longer transfer ownership to another user.
The default Tenant Admin role will not be impacted. Tenant admins can still transfer ownership to any user with the appropriate access rights in the tenant.
How do I claim ownership of an automation?
As a User assigned a custom role with the Tenant Admin Automations scope,you can claim ownership of an automation by following these steps:
Navigate to the Automations section in the Administration Console
Locate the automation you want to claim ownership of, and click theActionsmenu (...)
Choose Claim ownership
This behavior change only applies to the Tenant Admin Automations scope when it is added to a custom role. Tenant admins can still transfer ownership to any user with the appropriate access rights in the tenant.
If you have any questions, we're happy to assist. Reply to this blog post or take your queries to our Support Chat.
Thank you for choosing Qlik, Qlik Support
...View More