QNAP has released security updates to address seven zero-day vulnerabilities in its network-attached storage (NAS) products after these flaws were exploited by security researchers during the Pwn2Own Ireland 2025 competition. The vulnerabilities affected QNAP's QTS and QuTS hero operating systems, as well as key applications including Hyper Data Protector, Malware Remover, and HBS 3 Hybrid Backup Sync. The exploits were demonstrated by teams such as Summoning Team, DEVCORE, Team DDOS, and a CyCraft technology intern, highlighting the critical nature of these security issues.
QNAP has provided patched versions for all affected software and strongly recommends that users update to the latest releases and change all passwords to enhance security. The company has published detailed advisories and instructions for updating both the operating systems and vulnerable applications through the QTS or QuTS hero interface. Regular updates and monitoring of product support status are advised to ensure ongoing protection against similar vulnerabilities.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
QNAP also released QuMagie 2.7.0 to address CVE-2025-52425, a critical SQL injection vulnerability that could lead to remote code execution. Users were advised to upgrade to the patched version as part of the broader security response.
QNAP released security updates to fix seven zero-day vulnerabilities in QTS, QuTS hero, Hyper Data Protector, Malware Remover, and HBS 3 Hybrid Backup Sync after their disclosure at Pwn2Own Ireland 2025. The company urged customers to update affected software promptly to reduce exploitation risk.
During the Pwn2Own Ireland 2025 competition, security researchers from Summoning Team, DEVCORE, Team DDOS, and a CyCraft technology intern successfully exploited seven zero-day vulnerabilities affecting QNAP QTS, QuTS hero, and related applications. The demonstrated flaws included issues enabling remote code execution, privilege escalation, and device compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcesocradar.io
Open sourcesecurityonline.info
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.