Critical QNAP QVR Pro Vulnerability Let Remote Attackers Gain Access to the System
ID: 2b42215a-ba30-566d-ba08-6175d6d16659
STIX ID: report--2b42215a-ba30-566d-ba08-6175d6d16659
Feed Name: cybersecurityNews.com
Threat Score
QNAP disclosed a critical vulnerability (CVE-2026-22898) in QVR Pro 2.7.x that permits remote unauthenticated access because of a missing authentication check. The flaw could allow attackers to access or manipulate surveillance configurations and video feeds and pivot within networks; QNAP has released a patch (upgrade to QVR Pro 2.7.4.1485 or later) and urges administrators to apply it immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
