CVE Tools
Back to feed
Patch released QTS patch-tuesday QuTS hero QNAP web-app

QNAP Patches 14 Vulnerabilities in QTS, QuTS hero, and QVP Devices

Daily CyberSecurity (securityonline.info)·By Do Son··2 min read
CVE Tools coverage

QNAP has released patches addressing 14 vulnerabilities affecting QTS, QuTS hero, QuTS cloud, and QVP devices, with issues including command injection, credential theft, and denial-of-service conditions. Reported CVE IDs include CVE-2025-66273, CVE-2025-66279, CVE-2026-22893, and CVE-2025-59382, which together enable attackers to execute commands, tamper with password reset flows, or crash services. Because NAS appliances are high-value targets reachable from the network edge, applying the fixed firmware updates (e.g., QTS 5.2.10, QuTS hero h5.2.9, QuTS cloud C5.2.9, QVP 2.8.0) is important even though no active exploitation has been confirmed.