QNAP has patched 14 vulnerabilities across QTS, QuTS hero, QuTS cloud, and QVP that affect NAS and surveillance appliances, with impacts ranging from denial of service and information disclosure to privilege escalation and remote code execution. The vendor’s advisory QSA-26-10 describes multiple bug classes, including command injection, buffer overflow, broken access control, URL injection, NULL pointer dereference, and uncontrolled resource consumption, and rates the issues as Important.
The most serious flaws include command injection vulnerabilities CVE-2025-66273, CVE-2025-66279, and CVE-2026-22893, which can allow arbitrary command execution through username handling or administrative APIs, including one privilege-escalation scenario. QNAP also fixed CVE-2025-59382, a password-reset URL manipulation issue that can expose credentials. Fixed releases include QVP 2.8.0, QuTS cloud C5.2.9, QTS 5.2.9.3499, and QuTS hero h5.2.9; administrators were urged to update immediately, avoid exposing management interfaces to the internet, and maintain snapshots and offline backups because internet-facing NAS devices are frequent ransomware targets.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
On June 24, 2026, a related QNAP security notice was published regarding the vulnerabilities addressed in QSA-26-10. The notice reiterated the importance of applying firmware and security updates promptly.
On June 17, 2026, QNAP released advisory QSA-26-10 covering 14 vulnerabilities affecting QTS, QuTS hero, QuTS cloud, and QVP. The issues included command injection, buffer overflow, broken access control, URL injection, NULL pointer dereference, and uncontrolled resource consumption flaws, and QNAP provided fixed versions for affected product lines.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.