logo

QNAP Fixes 14 Vulnerabilities in QTS, QuTS Hero, QuTS Cloud, and QVP

ID: dcbbeca4-e0e9-5ae7-b2e6-727914750c6d

STIX ID: report--dcbbeca4-e0e9-5ae7-b2e6-727914750c6d

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-06-22

Date Updated: 2026-06-22

Author: Divya

...
...

QNAP published advisory QSA-26-10 detailing 14 “Important” vulnerabilities affecting QTS, QuTS hero, QuTS cloud and QVP (notable CVEs include URL injection CVE-2025-59382, multiple command injection flaws CVE-2025-66273/66279/2026-22893, and several stack/NULL dereference issues) that can lead to credential harvesting, arbitrary command execution, denial-of-service, and crashes; patched firmware versions are available and administrators are strongly urged to update, restrict administrative access, and monitor for suspicious activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.