logo

QNAP and Veritas dump 30-plus vulns over the weekend

ID: 25c7e92b-7878-5fc5-bd49-33090424cbe5

STIX ID: report--25c7e92b-7878-5fc5-bd49-33090424cbe5

Feed Name: The Register (Security)

Threat Score
65/100

Date Published: 2024-11-26

Date Updated: 2026-04-26

Author: Connor Jones

...
...

QNAP released patches addressing 24 vulnerabilities across several NAS products—including two critical and multiple high-severity flaws that may allow code execution, privilege escalation, or data access—while also retracting and re-releasing a problematic firmware update; separately, Veritas disclosed seven critical deserialization vulnerabilities in Enterprise Vault (CVSSv3 9.8 preliminarily) that can lead to remote code execution via .NET Remoting, with mitigations available but full patches slated for a future major release.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.