VORANT. Threat Intelligence Sign in Get the full feed

QNAP patches 18 flaws across NAS products

high vulnerability

QNAP released security updates addressing 18 vulnerabilities in QTS, QuTS hero, QuMagie, License Center, and QVP that enable remote code execution, privilege escalation, and denial of service.

The French CERT (CERT-FR) has issued an advisory regarding multiple security vulnerabilities affecting QNAP network-attached storage products and associated software. The flaws impact QTS versions 5.2.7 through 5.2.9, QuTS hero h5.2.8, QuTS cloud c5.2.8, QuMagie photo management software, License Center, and QVP video platform. QNAP published two security bulletins (QSA-26-10 and QSA-26-35) on June 17, 2026, documenting 18 CVE-identified vulnerabilities.

The vulnerabilities enable various attack scenarios including remote code execution, privilege escalation, denial of service, security policy bypass, and data confidentiality breaches. QNAP has released patches addressing these issues: QTS 5.2.10, QuTS hero h5.2.9, QuTS cloud c5.2.9, QuMagie 2.9.1 and 2.10.0, License Center 2.0.42, and QVP 2.8.0. Organizations running affected QNAP products should prioritize patching, particularly given the potential for remote exploitation and the widespread deployment of QNAP NAS devices in enterprise and small-business environments.

Mentioned in this report

Vulnerabilities CVE-2025-59382CVE-2025-62851CVE-2025-62858CVE-2025-66273CVE-2025-66279CVE-2025-66280CVE-2025-66281CVE-2025-68405CVE-2026-22893CVE-2026-22899CVE-2026-24720CVE-2026-24724CVE-2026-26236CVE-2026-26237CVE-2026-26239CVE-2026-26240CVE-2026-26241CVE-2026-44083

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0762

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free