Gbhackers QNAP Addresses 14 Vulnerabilities in NAS and Surveillance Systems
Article Content
- •QNAP fixed 14 vulnerabilities in its NAS and surveillance systems with advisory QSA-26-10.
- •Critical vulnerabilities include command injection and memory safety issues, allowing potential system compromise.
- •Users are urged to update to the latest firmware versions to mitigate risks of exploitation.
QNAP has released security advisory QSA-26-10 to address 14 vulnerabilities in its NAS and surveillance platforms, including QTS, QuTS hero, QuTS cloud, and QVP (QVR Pro appliances). These vulnerabilities, disclosed on April 6, 2026, are categorized as having 'Important' severity. Notable issues include CVE-2025-59382, a URL injection flaw that could lead to credential harvesting, and several command injection vulnerabilities (CVE-2025-66273, CVE-2025-66279, CVE-2026-22893) that allow arbitrary command execution. Other critical vulnerabilities involve memory safety issues, such as stack and buffer overflows (CVE-2025-62858, CVE-2026-26239, CVE-2026-26241), which can cause service crashes. QNAP has released firmware updates to mitigate these vulnerabilities, urging users to update immediately to prevent exploitation. The vulnerabilities affect versions QTS 5.2.7, QuTS hero h5.2.8, QuTS cloud c5.2.8, and QVP 2.7.1.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (12)
Following this threat?
Track Qnap and CVE-2025-59382 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…