QNAP Patches 14 Vulnerabilities in QTS, QuTS hero, and QVP Devices
PatchQTSQuTS heroOur summary
QNAP has released patches addressing 14 vulnerabilities affecting QTS, QuTS hero, QuTS cloud, and QVP devices, with issues including command injection, credential theft, and denial-of-service conditions. Reported CVE IDs include CVE-2025-66273, CVE-2025-66279, CVE-2026-22893, and CVE-2025-59382, which together enable attackers to execute commands, tamper with password reset flows, or crash services. Because NAS appliances are high-value targets reachable from the network edge, applying the fixed firmware updates (e.g., QTS 5.2.10, QuTS hero h5.2.9, QuTS cloud C5.2.9, QVP 2.8.0) is important even though no active exploitation has been confirmed.
Daily CyberSecurity (securityonline.info) publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.