HomeSecurityAttention! Multiple vulnerabilities in QNAP NAS devices - Patch now

Warning! Multiple vulnerabilities in QNAP NAS devices – Patch now

A series of vulnerabilities in QNAP NAS has raised concerns in the cybersecurity community after researchers identified weaknesses that could allow attackers to execute arbitrary commands, bypass security checks, disclose sensitive information, or disrupt system operation. The issues affect several QNAP platforms, including QTS, QuTS hero, QuTS cloud, and QVP devices.

Article image: Multiple Vulnerabilities in QNAP NAS Devices Resolved Through Security Updates

The security advisory, codenamed QSA-26-10, was issued by QNAP on June 17, 2026, and a related security notice was published today, June 24. The vulnerabilities were rated “Important” and have now been patched through software updates.

QNAP NAS: Which products are affected by the vulnerabilities

The QNAP NAS vulnerabilities affect QTS 5.2.7, QuTS hero h5.2.8, QuTS cloud c5.2.8, and QVP 2.7.1. Successful exploitation could lead to denial-of-service, information disclosure, elevation of privilege, remote code execution, and bypass of security restrictions.

See also: QNAP patches six Rsync vulnerabilities in NAS app

One of the most notable vulnerabilities, CVE-2025-59382, is a URL injection. QNAP explained that “a remote attacker can modify the password reset URL and trick a victim into visiting an attacker-controlled password reset page, leading to credential theft.”

Command Injection and Buffer Overflow 

Several vulnerabilities command injection. CVE-2025-66273 allows an authenticated administrator to inject arbitrary system commands via a username parameter. Similar command execution issues were identified in CVE-2025-66279, which affects user deletion APIs, and CVE-2026-22893, which could allow elevated command execution.

Additional vulnerabilities in QNAP NAS devices involve memory management weaknesses. CVE-2025-62858 is a user stack overflow vulnerability that can cause memory corruption and unexpected behavior when exploited by an administrator. CVE-2025-66280 and CVE-2025-68405 can lead to unexpected system behavior or denial-of-service situations.

See also: iOS 26.1: Apple fixes multiple security vulnerabilities

QNAP also disclosed three buffer overflow vulnerabilities: CVE-2026-26239, CVE-2026-26240, and CVE-2026-26241. These vulnerabilities can allow unauthorized actions or cause CGI service interruptions via excessively long file names during file upload.

Warning! Multiple vulnerabilities in QNAP NAS devices - Patch now

Access Control and Resource Consumption Issues

Among other QNAP NAS vulnerabilities, CVE-2026-24724 involves a “broken” access control that could allow authenticated users to bypass restrictions and access sensitive files. Meanwhile, CVE-2026-22899 can cause NULL pointer dereference in utilRequest.cgi, leading to a denial-of-service condition.

There's also CVE-2026-24720, a vulnerability resource consumption that could cause excessive CPU and memory usage, reducing overall system responsiveness. Finally, QNAP warned that CVE-2025-66281 can be triggered via a malformed HTTP request with a missing or empty content-length header.

See also: Cisco: Acquisition of WideField Security to strengthen cybersecurity

QNAP has released fixes for all affected products. The fixes are available in QVP 2.8.0, QuTS cloud C5.2.9, QTS 5.2.9.3499, and QuTS hero h5.2.9.

The disclosure of new vulnerabilities in QNAP NAS products is a reminder that network storage devices remain one of the most attractive targets for cybercriminals, as they often host critical corporate data, backups, and sensitive user information. Weaknesses such as remote code execution, elevation of privilege, and bypass of access controls can turn a NAS server into an entry point for larger attacks, with potential consequences including data leakage, service disruption, or even ransomware deployment.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Warning! Multiple vulnerabilities in QNAP NAS devices - Patch now

QNAP’s prompt release of patches is an important step in mitigating the risk, but the responsibility does not stop with the manufacturer. System administrators and organizations using affected platforms should proceed without delay to install updates, review access policies, and implement additional security measures, such as multi-factor authentication and limiting NAS device exposure to the internet. In an environment where cyber threats are constantly evolving, timely vulnerability management has become a prerequisite for ensuring business continuity and data protection.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS