logo

Is Your QNAP NAS Secure? Critical Patches Released for Major Vulnerabilities

ID: 55213b01-45ea-551e-8165-0338da4e8dd4

STIX ID: report--55213b01-45ea-551e-8165-0338da4e8dd4

Feed Name: The Cyber Express

Threat Score
75/100

Date Published: 2024-12-10

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

This report summarizes multiple critical vulnerabilities in QNAP NAS operating systems (QTS and QuTS hero), listing CVEs for issues such as remote code execution, command and format-string injection, CRLF injection, and authentication/certificate validation flaws affecting millions of devices; it provides affected versions, patched firmware releases, and practical update/mitigation steps including firmware update procedures, 2FA, access restrictions, and backups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.