CVE Tools

QNAP Patches 14 Vulnerabilities in QTS, QuTS hero, and QVP Devices

Daily CyberSecurity (securityonline.info)By Do Son

PatchQTSQuTS hero

Our summary

QNAP has released patches addressing 14 vulnerabilities affecting QTS, QuTS hero, QuTS cloud, and QVP devices, with issues including command injection, credential theft, and denial-of-service conditions. Reported CVE IDs include CVE-2025-66273, CVE-2025-66279, CVE-2026-22893, and CVE-2025-59382, which together enable attackers to execute commands, tamper with password reset flows, or crash services. Because NAS appliances are high-value targets reachable from the network edge, applying the fixed firmware updates (e.g., QTS 5.2.10, QuTS hero h5.2.9, QuTS cloud C5.2.9, QVP 2.8.0) is important even though no active exploitation has been confirmed.

Read at Daily CyberSecurity (securityonline.info)

Daily CyberSecurity (securityonline.info) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store