{"api_version":"1","generated_at":"2026-06-14T08:59:40+00:00","cve":"CVE-2026-41539","urls":{"html":"https://cve.report/CVE-2026-41539","api":"https://cve.report/api/cve/CVE-2026-41539.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-41539","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-41539"},"summary":{"title":"QTS, QuTS hero","description":"A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to bypass security mechanisms or read application data.\n\nWe have already fixed the vulnerability in the following versions:\nQTS 5.2.9.3492 build 20260507 and later\nQuTS hero h5.2.9.3499 build 20260514 and later\nQuTS hero h5.3.4.3500 build 20260520 and later\nQuTS hero h6.0.0.3500 build 20260520 and later","state":"PUBLISHED","assigner":"qnap","published_at":"2026-06-09 06:16:53","updated_at":"2026-06-12 15:37:43"},"problem_types":["CWE-79","CWE-79 CWE-79"],"metrics":[{"version":"4.0","source":"security@qnapsecurity.com.tw","type":"Secondary","score":"8.7","severity":"HIGH","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"8.7","severity":"HIGH","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","data":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.7,"baseSeverity":"HIGH","exploitMaturity":"UNREPORTED","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"PASSIVE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"}},{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"6.1","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}}],"references":[{"url":"https://www.qnap.com/en/security-advisory/qsa-26-31","name":"https://www.qnap.com/en/security-advisory/qsa-26-31","refsource":"security@qnapsecurity.com.tw","tags":["Broken Link"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-41539","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41539","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"QNAP Systems Inc.","product":"QTS","version":"affected 5.2.0 5.2.9.3492 build 20260507 custom","platforms":[]},{"source":"CNA","vendor":"QNAP Systems Inc.","product":"QuTS hero","version":"affected h5.2.0 h5.2.9.3499 build 20260514 custom","platforms":[]},{"source":"CNA","vendor":"QNAP Systems Inc.","product":"QuTS hero","version":"affected h5.3.0 h5.3.4.3500 build 20260520 custom","platforms":[]},{"source":"CNA","vendor":"QNAP Systems Inc.","product":"QuTS hero","version":"affected ? h6.0.0.3500 build 20260520 custom","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"We have already fixed the vulnerability in the following versions:\nQTS 5.2.9.3492 build 20260507 and later\nQuTS hero h5.2.9.3499 build 20260514 and later\nQuTS hero h5.3.4.3500 build 20260520 and later\nQuTS hero h6.0.0.3500 build 20260520 and later","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"qts","cpe6":"5.2.0.2737","cpe7":"build_20240417","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"qts","cpe6":"5.2.0.2744","cpe7":"build_20240424","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"qts","cpe6":"5.2.0.2782","cpe7":"build_20240601","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"qts","cpe6":"5.2.0.2802","cpe7":"build_20240620","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"qts","cpe6":"5.2.0.2823","cpe7":"build_20240711","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"qts","cpe6":"5.2.0.2851","cpe7":"build_20240808","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"qts","cpe6":"5.2.0.2860","cpe7":"build_20240817","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"qts","cpe6":"5.2.1.2930","cpe7":"build_20241025","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"qts","cpe6":"5.2.2.2950","cpe7":"build_20241114","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"qts","cpe6":"5.2.3.3006","cpe7":"build_20250108","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"qts","cpe6":"5.2.4.3070","cpe7":"build_20250312","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"qts","cpe6":"5.2.4.3079","cpe7":"build_20250321","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"qts","cpe6":"5.2.4.3092","cpe7":"build_20250403","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"qts","cpe6":"5.2.5.3145","cpe7":"build_20250526","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"qts","cpe6":"5.2.6.3195","cpe7":"build_20250715","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"qts","cpe6":"5.2.6.3229","cpe7":"build_20250818","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"qts","cpe6":"5.2.7.3256","cpe7":"build_20250913","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"qts","cpe6":"5.2.7.3297","cpe7":"build_20251024","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"qts","cpe6":"5.2.8.3332","cpe7":"build_20251128","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"qts","cpe6":"5.2.8.3350","cpe7":"build_20251216","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"qts","cpe6":"5.2.8.3359","cpe7":"build_20251225","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"qts","cpe6":"5.2.9.3410","cpe7":"build_20260214","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"qts","cpe6":"5.2.9.3451","cpe7":"build_20260327","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"quts_hero","cpe6":"h5.2.0.2737","cpe7":"build_20240417","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"quts_hero","cpe6":"h5.2.0.2782","cpe7":"build_20240601","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"quts_hero","cpe6":"h5.2.0.2789","cpe7":"build_20240607","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"quts_hero","cpe6":"h5.2.0.2802","cpe7":"build_20240620","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"quts_hero","cpe6":"h5.2.0.2823","cpe7":"build_20240711","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"quts_hero","cpe6":"h5.2.0.2851","cpe7":"build_20240808","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"quts_hero","cpe6":"h5.2.0.2860","cpe7":"build_20240817","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"quts_hero","cpe6":"h5.2.1.2929","cpe7":"build_20241025","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"quts_hero","cpe6":"h5.2.1.2940","cpe7":"build_20241105","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"quts_hero","cpe6":"h5.2.2.2952","cpe7":"build_20241116","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"quts_hero","cpe6":"h5.2.3.3006","cpe7":"build_20250108","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"quts_hero","cpe6":"h5.2.4.3070","cpe7":"build_20250312","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"quts_hero","cpe6":"h5.2.4.3079","cpe7":"build_20250321","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"quts_hero","cpe6":"h5.2.5.3138","cpe7":"build_20250519","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"quts_hero","cpe6":"h5.2.6.3195","cpe7":"build_20250715","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"quts_hero","cpe6":"h5.2.7.3256","cpe7":"build_20250913","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"quts_hero","cpe6":"h5.2.7.3297","cpe7":"build_20251024","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"quts_hero","cpe6":"h5.2.8.3321","cpe7":"build_20251117","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"quts_hero","cpe6":"h5.2.8.3350","cpe7":"build_20251216","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"quts_hero","cpe6":"h5.2.8.3359","cpe7":"build_20251225","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"quts_hero","cpe6":"h5.2.9.3410","cpe7":"build_20260214","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"quts_hero","cpe6":"h5.2.9.3492","cpe7":"build_20260507","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"quts_hero","cpe6":"h5.3.0.3115","cpe7":"build_20250430","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"quts_hero","cpe6":"h5.3.0.3145","cpe7":"build_20250530","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"quts_hero","cpe6":"h5.3.0.3192","cpe7":"build_20250716","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"quts_hero","cpe6":"h5.3.1.3250","cpe7":"build_20250912","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"quts_hero","cpe6":"h5.3.1.3292","cpe7":"build_20251024","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"quts_hero","cpe6":"h5.3.2.3354","cpe7":"build_20251225","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"quts_hero","cpe6":"h5.3.3.3424","cpe7":"build_20260305","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"quts_hero","cpe6":"h6.0.0.3324","cpe7":"build_20251125","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"quts_hero","cpe6":"h6.0.0.3382","cpe7":"build_20260122","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"quts_hero","cpe6":"h6.0.0.3397","cpe7":"build_20260206","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"41539","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qnap","cpe5":"quts_hero","cpe6":"h6.0.0.3459","cpe7":"build_20260409","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"41539","cve":"CVE-2026-41539","epss":"0.000730000","percentile":"0.225170000","score_date":"2026-06-13","updated_at":"2026-06-14 00:08:31"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-41539","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-06-09T13:12:29.346617Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-06-09T13:12:39.716Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"QTS","vendor":"QNAP Systems Inc.","versions":[{"lessThan":"5.2.9.3492 build 20260507","status":"affected","version":"5.2.0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"QuTS hero","vendor":"QNAP Systems Inc.","versions":[{"lessThan":"h5.2.9.3499 build 20260514","status":"affected","version":"h5.2.0","versionType":"custom"},{"lessThan":"h5.3.4.3500 build 20260520","status":"affected","version":"h5.3.0","versionType":"custom"},{"lessThan":"h6.0.0.3500 build 20260520","status":"affected","version":"?","versionType":"custom"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to bypass security mechanisms or read application data.<br><br>We have already fixed the vulnerability in the following versions:<br>QTS 5.2.9.3492 build 20260507 and later<br>QuTS hero h5.2.9.3499 build 20260514 and later<br>QuTS hero h5.3.4.3500 build 20260520 and later<br>QuTS hero h6.0.0.3500 build 20260520 and later<br>"}],"value":"A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to bypass security mechanisms or read application data.\n\nWe have already fixed the vulnerability in the following versions:\nQTS 5.2.9.3492 build 20260507 and later\nQuTS hero h5.2.9.3499 build 20260514 and later\nQuTS hero h5.3.4.3500 build 20260520 and later\nQuTS hero h6.0.0.3500 build 20260520 and later"}],"impacts":[{"capecId":"CAPEC-63","descriptions":[{"lang":"en","value":"CAPEC-63"}]}],"metrics":[{"cvssV4_0":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.7,"baseSeverity":"HIGH","exploitMaturity":"UNREPORTED","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"PASSIVE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-79","description":"CWE-79","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-06-09T05:51:37.054Z","orgId":"2fd009eb-170a-4625-932b-17a53af1051f","shortName":"qnap"},"references":[{"url":"https://www.qnap.com/en/security-advisory/qsa-26-31"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"We have already fixed the vulnerability in the following versions:<br>QTS 5.2.9.3492 build 20260507 and later<br>QuTS hero h5.2.9.3499 build 20260514 and later<br>QuTS hero h5.3.4.3500 build 20260520 and later<br>QuTS hero h6.0.0.3500 build 20260520 and later<br>"}],"value":"We have already fixed the vulnerability in the following versions:\nQTS 5.2.9.3492 build 20260507 and later\nQuTS hero h5.2.9.3499 build 20260514 and later\nQuTS hero h5.3.4.3500 build 20260520 and later\nQuTS hero h6.0.0.3500 build 20260520 and later"}],"source":{"advisory":"QSA-26-31","discovery":"EXTERNAL"},"title":"QTS, QuTS hero","x_generator":{"engine":"Vulnogram 0.1.0-dev"}}},"cveMetadata":{"assignerOrgId":"2fd009eb-170a-4625-932b-17a53af1051f","assignerShortName":"qnap","cveId":"CVE-2026-41539","datePublished":"2026-06-09T05:51:37.054Z","dateReserved":"2026-04-21T03:07:17.287Z","dateUpdated":"2026-06-09T13:12:39.716Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-06-09 06:16:53","lastModifiedDate":"2026-06-12 15:37:43","problem_types":["CWE-79","CWE-79 CWE-79"],"metrics":{"cvssMetricV40":[{"source":"security@qnapsecurity.com.tw","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:qts:5.2.0.2737:build_20240417:*:*:*:*:*:*","matchCriteriaId":"F4026A4B-7AB4-48EA-971D-88DFDD3F01A7"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:qts:5.2.0.2744:build_20240424:*:*:*:*:*:*","matchCriteriaId":"1F3F99BB-0D68-4D74-92C8-59E24F96C50D"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:qts:5.2.0.2782:build_20240601:*:*:*:*:*:*","matchCriteriaId":"1DE63B4D-8E84-41D3-B1F3-04AE6040242B"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:qts:5.2.0.2802:build_20240620:*:*:*:*:*:*","matchCriteriaId":"75746563-C648-4E55-9126-703F915F8B8A"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:qts:5.2.0.2823:build_20240711:*:*:*:*:*:*","matchCriteriaId":"AF6BA027-A635-4E90-80C8-130B10AB3D23"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:qts:5.2.0.2851:build_20240808:*:*:*:*:*:*","matchCriteriaId":"5406F242-A215-4B07-809F-7A7CE55ACE71"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:qts:5.2.0.2860:build_20240817:*:*:*:*:*:*","matchCriteriaId":"FA17778E-B3B1-44DD-B4E9-5AD25A3E804C"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:qts:5.2.1.2930:build_20241025:*:*:*:*:*:*","matchCriteriaId":"E3FC6646-2247-4ED9-9643-CD376674E2E7"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:qts:5.2.2.2950:build_20241114:*:*:*:*:*:*","matchCriteriaId":"62170342-067D-442C-88FB-64A4BEA8AFE4"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:qts:5.2.3.3006:build_20250108:*:*:*:*:*:*","matchCriteriaId":"82464467-E1E6-47E1-BDE5-DDFA52994A47"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:qts:5.2.4.3070:build_20250312:*:*:*:*:*:*","matchCriteriaId":"75AE902C-0516-4341-9BF0-21D8803E091C"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:qts:5.2.4.3079:build_20250321:*:*:*:*:*:*","matchCriteriaId":"5B005D70-8C91-48D4-B09A-9EBE2E9E5090"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:qts:5.2.4.3092:build_20250403:*:*:*:*:*:*","matchCriteriaId":"82FE5F89-A0E1-4D1B-A363-0A0D4141F502"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:qts:5.2.5.3145:build_20250526:*:*:*:*:*:*","matchCriteriaId":"B21A9EE0-88D5-42D9-BA21-D55518FCC6E4"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:qts:5.2.6.3195:build_20250715:*:*:*:*:*:*","matchCriteriaId":"3B575CF2-21F3-4435-B6B4-61D79B34429C"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:qts:5.2.6.3229:build_20250818:*:*:*:*:*:*","matchCriteriaId":"E2EBD305-91E3-4BCC-835B-4878DF4DA3B8"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:qts:5.2.7.3256:build_20250913:*:*:*:*:*:*","matchCriteriaId":"554CB021-1477-4E63-8EBA-74056B4D8DA7"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:qts:5.2.7.3297:build_20251024:*:*:*:*:*:*","matchCriteriaId":"153F90E1-A54F-4B8D-AEEA-4643421AFF7F"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:qts:5.2.8.3332:build_20251128:*:*:*:*:*:*","matchCriteriaId":"EBDC5E20-6EF7-41B4-AEB7-6F2181BD8B50"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:qts:5.2.8.3350:build_20251216:*:*:*:*:*:*","matchCriteriaId":"98ECCF6B-D31F-45D6-A993-F4218B030748"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:qts:5.2.8.3359:build_20251225:*:*:*:*:*:*","matchCriteriaId":"1C4670D1-845B-4C06-A9B7-CB7D149E59AA"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:qts:5.2.9.3410:build_20260214:*:*:*:*:*:*","matchCriteriaId":"7E9B4AEC-E179-4F05-9E63-E934AAAB4210"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:qts:5.2.9.3451:build_20260327:*:*:*:*:*:*","matchCriteriaId":"AE86A258-45D5-469C-A9C8-B5A986AA4358"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:quts_hero:h5.2.0.2737:build_20240417:*:*:*:*:*:*","matchCriteriaId":"CDCBB36A-CB91-4BA3-A6ED-952E6A4A0481"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:quts_hero:h5.2.0.2782:build_20240601:*:*:*:*:*:*","matchCriteriaId":"240BCFF1-CCCB-4C07-8E2C-7F43F68407FC"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:quts_hero:h5.2.0.2789:build_20240607:*:*:*:*:*:*","matchCriteriaId":"D3AF7276-77E0-474A-B10F-AC15BC5FCF00"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:quts_hero:h5.2.0.2802:build_20240620:*:*:*:*:*:*","matchCriteriaId":"5FA8C3EC-B6C0-44A8-BC91-18E3E90C63AB"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:quts_hero:h5.2.0.2823:build_20240711:*:*:*:*:*:*","matchCriteriaId":"889336D2-D9F7-4CC0-A22F-B837B5E77751"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:quts_hero:h5.2.0.2851:build_20240808:*:*:*:*:*:*","matchCriteriaId":"98F72EB9-0EE3-416A-B9BB-2512F5203A5A"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:quts_hero:h5.2.0.2860:build_20240817:*:*:*:*:*:*","matchCriteriaId":"9110382F-57C2-4C2E-82D1-3246C882B2C3"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:quts_hero:h5.2.1.2929:build_20241025:*:*:*:*:*:*","matchCriteriaId":"DB92EFD7-47DD-4AAC-97BD-A2D4918FF4ED"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:quts_hero:h5.2.1.2940:build_20241105:*:*:*:*:*:*","matchCriteriaId":"78E38E23-1AD0-49E1-89FA-73DC2F496137"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:quts_hero:h5.2.2.2952:build_20241116:*:*:*:*:*:*","matchCriteriaId":"F2F302B6-26CC-4044-B480-4EBDBB90797F"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:quts_hero:h5.2.3.3006:build_20250108:*:*:*:*:*:*","matchCriteriaId":"BF0093B6-8D38-4D1E-AD71-79299123C2B1"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:quts_hero:h5.2.4.3070:build_20250312:*:*:*:*:*:*","matchCriteriaId":"48A3CDAA-B0C6-4280-B1AC-DDD027F9D632"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:quts_hero:h5.2.4.3079:build_20250321:*:*:*:*:*:*","matchCriteriaId":"1807DE4F-CDF3-4E3B-ADC1-9535EF1D60FE"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:quts_hero:h5.2.5.3138:build_20250519:*:*:*:*:*:*","matchCriteriaId":"68FF7342-A0AF-4E75-9CD6-D584B450B8AB"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:quts_hero:h5.2.6.3195:build_20250715:*:*:*:*:*:*","matchCriteriaId":"A8E84E3D-943C-4DF5-86D3-DCAC3C034B81"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:quts_hero:h5.2.7.3256:build_20250913:*:*:*:*:*:*","matchCriteriaId":"17720E05-1BBF-4605-A777-FA4059B3C2DC"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:quts_hero:h5.2.7.3297:build_20251024:*:*:*:*:*:*","matchCriteriaId":"39CB5F1C-9811-499D-9D32-34B40E0D475E"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:quts_hero:h5.2.8.3321:build_20251117:*:*:*:*:*:*","matchCriteriaId":"207E47AF-AADA-4A44-B0D6-3F8CE0285D46"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:quts_hero:h5.2.8.3350:build_20251216:*:*:*:*:*:*","matchCriteriaId":"EC6DAFB2-9BB7-4412-B1D4-3EFFD92E5493"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:quts_hero:h5.2.8.3359:build_20251225:*:*:*:*:*:*","matchCriteriaId":"91FEA769-B445-4BD6-ABD0-652D05C10E05"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:quts_hero:h5.2.9.3410:build_20260214:*:*:*:*:*:*","matchCriteriaId":"02D7654E-06DB-40B8-86D8-E81F4415CC95"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:quts_hero:h5.2.9.3492:build_20260507:*:*:*:*:*:*","matchCriteriaId":"1E7F05AA-493E-4166-8C8A-C295B8F223CA"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:quts_hero:h5.3.0.3115:build_20250430:*:*:*:*:*:*","matchCriteriaId":"4175C7F7-E946-41C6-8863-E23233B91A2B"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:quts_hero:h5.3.0.3145:build_20250530:*:*:*:*:*:*","matchCriteriaId":"DE16C73E-9291-44FD-A9CB-B7C127E67A6F"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:quts_hero:h5.3.0.3192:build_20250716:*:*:*:*:*:*","matchCriteriaId":"ED4023E4-6C28-413A-B7B1-6CEEBC48A1C0"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:quts_hero:h5.3.1.3250:build_20250912:*:*:*:*:*:*","matchCriteriaId":"0A94FE59-675E-4FF1-B971-F5A0A7B98EA7"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:quts_hero:h5.3.1.3292:build_20251024:*:*:*:*:*:*","matchCriteriaId":"92CE2B8B-4A23-41AA-94C6-D0DBFE06FDC1"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:quts_hero:h5.3.2.3354:build_20251225:*:*:*:*:*:*","matchCriteriaId":"823CEFF6-8365-476D-9D90-8F51BA749424"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:quts_hero:h5.3.3.3424:build_20260305:*:*:*:*:*:*","matchCriteriaId":"6B780AFB-CCC5-4AD8-A3C2-2F0AC18F4B09"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:quts_hero:h6.0.0.3324:build_20251125:*:*:*:*:*:*","matchCriteriaId":"ACAAA533-F83E-400F-8D83-84C086845944"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:quts_hero:h6.0.0.3382:build_20260122:*:*:*:*:*:*","matchCriteriaId":"5BC82832-F0A7-4096-9A5A-80D2374B6028"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:quts_hero:h6.0.0.3397:build_20260206:*:*:*:*:*:*","matchCriteriaId":"5D71766D-12E7-44AC-80EB-3D778FEED6F4"},{"vulnerable":true,"criteria":"cpe:2.3:o:qnap:quts_hero:h6.0.0.3459:build_20260409:*:*:*:*:*:*","matchCriteriaId":"BB658425-783E-49FD-A8F9-3FAD3BDB2689"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"41539","Ordinal":"1","Title":"QTS, QuTS hero","CVE":"CVE-2026-41539","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"41539","Ordinal":"1","NoteData":"A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to bypass security mechanisms or read application data.\n\nWe have already fixed the vulnerability in the following versions:\nQTS 5.2.9.3492 build 20260507 and later\nQuTS hero h5.2.9.3499 build 20260514 and later\nQuTS hero h5.3.4.3500 build 20260520 and later\nQuTS hero h6.0.0.3500 build 20260520 and later","Type":"Description","Title":"QTS, QuTS hero"}]}}}