Skip to content
Security updates: Various attacks on Qnap NAS possible

Security updates: Various attacks on Qnap NAS possible

Heise.De • January 5, 2026

Multiple security vulnerabilities endanger Qnap NAS systems. Security patches are available for download. However, in many cases, attacks are not straightforward.

As indicated in the security section of the Qnap website , the vulnerabilities affect License Center, MARS, Qfiling, Qfinder Pro, Qsync, QuMagie, QVPN Device Client, QTS, and QuTS hero. Admins can find information on the security updates in the advisories linked below this post.

Remote attackers can exploit a vulnerability (CVE-2025-59384 " high ") in Qfiling, among other things, to view system data. The NAS operating systems QTS and QuTS hero are vulnerable through multiple flaws. For example, attackers can disable NAS systems via DoS attacks or access actually protected, secret data. However, attackers must have already gained control of an admin account to do so. An official classification of the threat level of these vulnerabilities on the NIST website is apparently still pending. CERT Bund from the Federal Office for Information Security (BSI) classifies the severity as " high ".

So far, there are no reports of attackers exploiting the vulnerabilities. It is also currently unclear how to identify already attacked instances.

Further information on security patches:

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.

Extracted Entities

Attack Types (1)

Platforms (2)