QNAP Fixes 14 Vulnerabilities in QTS, QuTS Hero, QuTS Cloud, and QVP
ID: dcbbeca4-e0e9-5ae7-b2e6-727914750c6d
STIX ID: report--dcbbeca4-e0e9-5ae7-b2e6-727914750c6d
Feed Name: GBHackers
QNAP published advisory QSA-26-10 detailing 14 “Important” vulnerabilities affecting QTS, QuTS hero, QuTS cloud and QVP (notable CVEs include URL injection CVE-2025-59382, multiple command injection flaws CVE-2025-66273/66279/2026-22893, and several stack/NULL dereference issues) that can lead to credential harvesting, arbitrary command execution, denial-of-service, and crashes; patched firmware versions are available and administrators are strongly urged to update, restrict administrative access, and monitor for suspicious activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
