Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · qnap

qnap

· 74 Critical

Total CVEs

629

Critical

74

Products

146

Search All CVEs →

629

Products (146)

qts313 CVEsquts hero240 CVEsqutscloud70 CVEsqsync central62 CVEsfile station54 CVEsphoto station26 CVEsvideo station15 CVEsqumagie13 CVEsmedia streaming add-on13 CVEsmusic station13 CVEsqurouter12 CVEsnas11 CVEshelpdesk11 CVEsqvr10 CVEsqulog center8 CVEsq\'center7 CVEsnas proxy server7 CVEsqvr pro6 CVEslicense center6 CVEshybrid backup sync6 CVEsnotes station 36 CVEsqunetswitch5 CVEsmultimedia console5 CVEsqvr elite5 CVEsqvr guard5 CVEsqes4 CVEsviostor network video recorder3 CVEsdownload station3 CVEssignage station3 CVEssurveillance station3 CVEsqcalagent3 CVEsqufirewall3 CVEsqvp-21a3 CVEsqvp-21a firmware3 CVEsqvp-41a3 CVEsqvp-41a firmware3 CVEsqvp-41b3 CVEsqvp-41b firmware3 CVEsqvp-63a3 CVEsqvp-63a firmware3 CVEsqvp-63b3 CVEsqvp-63b firmware3 CVEsqvp-85a3 CVEsqvp-85a firmware3 CVEsqvp-85b3 CVEsqvp-85b firmware3 CVEsqvpn3 CVEsts-639 pro turbo nas2 CVEshyper data protector2 CVEsmyqnapcloud link2 CVEsmyqnapcloud2 CVEsqsw-m2108r-2c2 CVEsqsw-m2108-2s2 CVEsqusbcam22 CVEsqsw-m2108-2c2 CVEsqss2 CVEsmalware remover2 CVEsts-239 pro turbo nas2 CVEsqmailagent2 CVEskazoo server2 CVEsnetbak replicator2 CVEsiartist lite2 CVEssurveillance station pro2 CVEsq\'center virtual appliance2 CVEsts-469u1 CVEsts-469u firmware1 CVEsai core1 CVEsts-639 pro firmware1 CVEsts-ec1679u-rp1 CVEsts-ec1679u-rp firmware1 CVEsviocard-1001 CVEsviocard-100 firmware1 CVEsviocard-301 CVEsviocard-3001 CVEsviocard-300 firmware1 CVEsviocard-30 firmware1 CVEsviocard 3001 CVEsviocard 300 firmware1 CVEsviogate-3401 CVEsviogate-340 firmware1 CVEsviogate-340a1 CVEsviogate-340a firmware1 CVEsts-639 pro1 CVEsauthenticator1 CVEscontainer station1 CVEsej16001 CVEsej1600 firmware1 CVEshybriddesk station1 CVEsimage2pdf1 CVEsnotification center1 CVEsnvr storage expansion1 CVEsnvr storage expansion firmware1 CVEsphoto station firmware1 CVEsqfile1 CVEsqfiling1 CVEsqfinder pro1 CVEsqgd-1600p1 CVEsqgd-1602p1 CVEsqgd-3014pt1 CVEsqsw-m2116p-2t2s1 CVEsqsw-m2116p-2t2s firmware1 CVEsqsw-m4081 CVEsqsync1 CVEsqts helpdesk1 CVEsquftp1 CVEsqvr firmware1 CVEsqvr pro client1 CVEsqvr smart client1 CVEsragic cloud db1 CVEsroon server1 CVEssinage station1 CVEssmb service1 CVEsss-8391 CVEsss-839 firmware1 CVEstl-d1600s1 CVEstl-d1600s firmware1 CVEstl-d400s1 CVEstl-d400s firmware1 CVEstl-d800c1 CVEstl-d800c firmware1 CVEstl-d800s1 CVEstl-d800s firmware1 CVEstl-r1200c-rp1 CVEstl-r1200c-rp firmware1 CVEstl-r1200s-rp1 CVEstl-r1200s-rp firmware1 CVEstl-r1220sep-rp1 CVEstl-r1220sep-rp firmware1 CVEstl-r1620sdc1 CVEstl-r1620sdc firmware1 CVEstl-r1620sep-rp1 CVEstl-r1620sep-rp firmware1 CVEstl-r400s1 CVEstl-r400s firmware1 CVEstr-0021 CVEstr-002 firmware1 CVEstr-0041 CVEstr-004 firmware1 CVEstr-004u1 CVEstr-004u firmware1 CVEsts-212p1 CVEsts-212p firmware1 CVEsts-239 pro1 CVEsts-239 pro firmware1 CVEsts-459u1 CVEsts-459u firmware1 CVEs

Recent Vulnerabilities

View all 629
CVE-2026-26241CRITICAL 9.1

A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5243 and later

CVE-2026-26240CRITICAL 9.1

A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5243 and later

CVE-2026-26239HIGH 8.1

A buffer overflow vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5208 and later

CVE-2026-26237HIGH 7.5

A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized actions. We have already fixed the vulnerability in the following version: QuMagie 2.9.0 and later

CVE-2026-24724HIGH 8.1

An incorrect authorization vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass intended access restrictions. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5243 and later

CVE-2026-24720MEDIUM 6.5

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5243 and later

CVE-2026-24717MEDIUM 6.5

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3492 build 20260507 and later QuTS hero h5.2.9.3499 build 20260514 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3459 build 20260409 and later

CVE-2026-22899MEDIUM 6.5

A NULL pointer dereference vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5208 and later

CVE-2025-62851MEDIUM 4.4

A path traversal vulnerability has been reported to affect License Center. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: License Center 1.9.56 and later

CVE-2025-62850HIGH 7.2

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QuTS hero h5.2.9.3410 build 20260214 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3459 build 20260409 and later

CVE-2025-66276CRITICAL 9.8

QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250913 and later

CVE-2025-58468HIGH 8.8

A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities. We have already fixed the vulnerability in the following version: Notification Center 1.10.0.3291 and later

CVE-2026-44083CRITICAL 9.8

An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to gain unintended privileges. We have already fixed the vulnerability in the following version: QuMagie 2.9.1 and later

CVE-2025-62858MEDIUM 6.5

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build 20260214 and later QuTS hero h5.2.9.3410 build 20260214 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3397 build 20260206 and later

CVE-2026-41539MEDIUM 6.1

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3492 build 20260507 and later QuTS hero h5.2.9.3499 build 20260514 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3500 build 20260520 and later

CVE-2026-26236HIGH 7.5

A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized actions. We have already fixed the vulnerability in the following version: QuMagie 2.9.0 and later

CVE-2026-22902MEDIUM 6.7

A command injection vulnerability has been reported to affect QuNetSwitch. If a local attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.5.0906 and later

CVE-2026-22901CRITICAL 9.8

A command injection vulnerability has been reported to affect QuNetSwitch. If a remote attacker gains a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.5.0906 and later

CVE-2026-22900CRITICAL 9.8

A use of hard-coded credentials vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to gain unauthorized access. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.5.0906 and later

CVE-2026-22898CRITICAL 9.8

A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers can then exploit the vulnerability to gain access to the system. We have already fixed the vulnerability in the following version: QVR Pro 2.7.4.14 and later

CVE-2026-22897CRITICAL 9.8

A command injection vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.4.0415 and later

CVE-2026-22895MEDIUM 4.8

A cross-site scripting (XSS) vulnerability has been reported to affect QuFTP Service. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: QuFTP Service 1.4.3 and later QuFTP Service 1.5.2 and later QuFTP Service 1.6.2 and later

CVE-2025-62846MEDIUM 6.7

An SQL injection vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: QuRouter 2.6.2.007 and later

CVE-2025-62845MEDIUM 6.7

An improper neutralization of escape, meta, or control sequences vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, they can then exploit the vulnerability to cause unexpected behavior. We have already fixed the vulnerability in the following version: QuRouter 2.6.3.009 and later

CVE-2025-62844MEDIUM 5.5

A weak authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they can then exploit the vulnerability to gain sensitive information. We have already fixed the vulnerability in the following version: QuRouter 2.6.2.007 and later