By vendor

Qnap vulnerabilities

Known CVEs affecting Qnap products, prioritized by severity, with SEC.co remediation and detection guidance.

18 published vulnerabilities

  • CVE-2026-24724HIGH 8.1

    CVE-2026-24724 is an authorization bypass vulnerability affecting QNAP File Station 6. An attacker with valid user credentials can exploit improper access control checks to gain unauthorized access to resources or functionality they should not be able to reach. The vulnerability requires an existing user account but does not require user interaction or special network conditions, making it a practical concern for environments where user account compromise is a realistic threat.

  • CVE-2026-26239HIGH 8.1

    A buffer overflow flaw in QNAP File Station 5 allows authenticated users to corrupt memory or crash the application. While the vulnerability requires an attacker to first obtain valid user credentials, the impact—potential system compromise and denial of service—warrants prompt patching. QNAP has released a fix in version 5.5.6.5208 and later.

  • CVE-2026-26236HIGH 7.5

    A missing authorization vulnerability in QuMagie allows remote attackers to access data or perform actions they should not be permitted to do. The flaw does not require authentication, meaning an unauthenticated attacker on the network can exploit it directly. The vulnerability affects confidentiality but not integrity or availability. QNAP has patched the issue in QuMagie version 2.9.0 and later.

  • CVE-2026-26237HIGH 7.5

    QuMagie, QNAP's media management application, contains a missing authorization vulnerability that allows remote attackers to access unauthorized data without requiring authentication. An attacker can exploit this flaw over the network to view or retrieve sensitive information stored within QuMagie installations. The vulnerability affects versions prior to 2.9.0 and has been patched in that release and later versions.

  • CVE-2025-62850HIGH 7.2

    A NULL pointer dereference flaw in QNAP QuTS hero operating system can allow an administrator account holder to crash the storage system, causing service interruption. The vulnerability requires valid admin credentials to exploit, limiting its immediate exposure to insider threats or compromised admin accounts. QNAP has released patched versions across multiple QuTS hero branches.

  • CVE-2025-66273HIGH 7.2

    QNAP NAS systems running vulnerable versions of QTS and QuTS hero contain a command injection flaw that allows an authenticated administrator to execute arbitrary commands on the device. An attacker who obtains admin credentials—either through credential compromise, social engineering, or internal threat—can leverage this vulnerability to gain full control over the NAS, potentially accessing stored data, modifying configurations, or using the device as a pivot point into the network. The vulnerability requires valid administrative access, so it represents a privilege escalation or lateral movement risk rather than an unauthenticated remote attack.

  • CVE-2025-66279HIGH 7.2

    A command injection flaw in QNAP operating systems allows an authenticated administrator to run arbitrary commands on affected NAS devices. The vulnerability requires valid admin credentials, limiting exposure to insider threats or attackers who have compromised an admin account. QNAP has patched multiple OS versions including QTS 5.2.9.3410 build 20260214 and later, and several QuTS hero releases.

  • CVE-2025-66280HIGH 7.2

    QNAP has patched an integer overflow vulnerability affecting their NAS operating systems. The flaw requires an attacker to first obtain administrator credentials, then exploit the memory handling weakness to gain elevated control or crash the system. While the barrier to entry is high—needing valid admin access—the potential impact is severe because it affects core system integrity. QNAP has released patched versions across QTS and QuTS hero product lines.

  • CVE-2025-66281HIGH 7.2

    CVE-2025-66281 is a NULL pointer dereference vulnerability affecting QNAP NAS operating systems. When triggered, the flaw causes the application to crash, resulting in a denial-of-service condition. An attacker with high-level administrative privileges can remotely exploit this to disrupt NAS availability. While the vulnerability requires elevated credentials to trigger, the impact is immediate and can leave your storage infrastructure offline until patched.

  • CVE-2026-22893HIGH 7.2

    A command injection flaw affects QNAP NAS operating systems. An attacker who obtains administrator credentials can use this vulnerability to run arbitrary commands on the affected device, potentially compromising data integrity, confidentiality, and availability. QNAP has released patched versions addressing this issue.

  • CVE-2026-24716HIGH 7.2

    A NULL pointer dereference flaw in QNAP NAS operating systems allows authenticated administrators to crash the system and cause a denial-of-service. An attacker must already have administrator credentials to exploit this vulnerability, which limits the attack surface but remains a significant risk for organizations where admin accounts may be compromised or insider threats exist. QNAP has released patched versions across multiple OS lines to address this issue.

  • CVE-2026-24719HIGH 7.2

    QNAP has patched a command injection vulnerability affecting their NAS operating systems. An attacker who already has administrator credentials can use this flaw to run arbitrary commands on affected devices. While the vulnerability requires administrative access (limiting who can exploit it), the ability to execute unrestricted commands on a NAS—which often stores critical business data and backups—makes this a meaningful risk. QNAP has issued fixes for QTS 5.2.9.3492 build 20260507 and later, and QuTS hero h5.2.9.3499 build 20260514 and later.

  • CVE-2025-62858MEDIUM 6.5

    A buffer overflow flaw exists in QNAP's QTS and QuTS hero operating systems that allows a high-privileged attacker to corrupt memory or crash running processes. Because the vulnerability requires prior administrative access, the risk is contained to scenarios where an admin account has been compromised or a trusted insider acts maliciously. QNAP has released patched versions across all affected product lines.

  • CVE-2026-22899MEDIUM 6.5

    A NULL pointer dereference flaw in QNAP File Station 6 allows authenticated users to crash the service, causing a denial-of-service condition. An attacker must first obtain valid user credentials to exploit this vulnerability. The issue does not compromise confidentiality or integrity—only availability. QNAP has released a patch for File Station 5 version 5.5.6.5208 and later; however, the advisory indicates File Station 6 remains affected, and a specific patched version for File Station 6 has not yet been disclosed in available vendor guidance.

  • CVE-2026-24717MEDIUM 6.5

    A path traversal vulnerability in QNAP operating systems allows an attacker who already has administrator credentials to read files and system data they shouldn't have access to. While the attacker needs valid admin account access first, once obtained, they can bypass file access restrictions to view sensitive information. QNAP has released patched versions across multiple OS lines to fix this issue.

  • CVE-2026-24720MEDIUM 6.5

    File Station 6, a QNAP file management product, contains a resource exhaustion vulnerability that allows authenticated users to consume system resources without limits, potentially starving other applications and processes of critical resources. An attacker with valid credentials could trigger conditions that degrade or block access for legitimate users and services on the same system.

  • CVE-2026-41539MEDIUM 6.1

    QNAP has patched a cross-site scripting (XSS) vulnerability affecting multiple versions of QTS and QuTS hero operating systems. The flaw allows remote attackers to inject malicious scripts that execute in users' browsers, potentially bypassing security controls or stealing sensitive application data. No authentication is required to attempt exploitation, but a user must be tricked into clicking a malicious link or visiting a compromised page. QNAP has released security updates addressing the issue across affected product lines.

  • CVE-2025-62851MEDIUM 4.4

    CVE-2025-62851 is a path traversal vulnerability affecting QNAP License Center that allows a local administrator to read files and system data they should not have access to. An attacker who already has administrative credentials can use this flaw to navigate the file system and extract sensitive information. The vulnerability has a CVSS score of 4.4 (Medium severity) and is addressed in License Center version 1.9.56 and later.