Known Vulnerabilities for QuTS Hero by QNAP Systems Inc.
Listed below are 10 of the newest known vulnerabilities associated with "QuTS Hero" by "QNAP Systems Inc.".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-41539 json | A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remote att... | Not Provided | 2026-06-09 | 2026-06-09 |
| CVE-2026-24719 json | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker ga... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-24717 json | A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-24716 json | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote atta... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-22893 json | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker ga... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2025-66281 json | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote attac... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2025-66280 json | An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If a remo... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2025-66279 json | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker ga... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2025-66276 json | QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250913 a... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2025-66274 json | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote atta... | Not Provided | 2026-02-11 | 2026-06-09 |