Critical 9.3 CVSS Flaw in QNAP QVR Pro Exposes Surveillance Systems
ID: a0acec76-4a27-5944-9d4d-7443cb52ba0d
STIX ID: report--a0acec76-4a27-5944-9d4d-7443cb52ba0d
Feed Name: securityonline.info
Threat Score
QNAP has disclosed a critical authentication-bypass vulnerability (CVE-2026-22898, CVSS 9.3) in QVR Pro 2.7.x that allows remote attackers to bypass login and gain full access to surveillance systems, including live feeds and recorded footage. A patched release (QVR Pro 2.7.4.1485 and later) is available and administrators are urged to update immediately via QTS/QuTS hero App Center.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
