The QNAPwatch hub is a vendor-specific view inside ITECS MSP Threat Radar. We pull the latest security advisories, incidents, and known-exploited CVEs directly from the official feeds below, score each one for MSP relevance, and surface what's most likely to need attention this week.
Confirm whether recent QNAP activity overlaps with your environment.
Prioritize advisories by MSP-relevance score, severity, and status.
Turn the signal into an assessment, briefing, or managed-service engagement with ITECS.
At a glance
Tracked
13
Active
11
Featured
12
Unique CVEs
13
Most recent entry
Mar 20, 2026, 12:16 PM
Feed refreshes daily · 5:15 a.m. Central
Sources·CISA KEV and NVD (product vendor coverage)
"Most recent entry" is the newest item the upstream feed has published — not our sync time.
Watch items
Recent QNAP watch items
Showing the 13 most recent items, newest first. Each row links to the official advisory.
13 rows · sorted newest first
Operations view
qvr pro vulnerability (CVE-2026-22898)
CRITICAL
watchNVDCVE-2026-22898
A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers can then exploit the vulnerability to gain access to the system.
We have already fixed the vulnerability in the following version:
QVR Pro 2.7.4.14 and later
media streaming add-on vulnerability (CVE-2025-59383)
LOW
watchNVDCVE-2025-59383
A buffer overflow vulnerability has been reported to affect Media Streaming Add-On. The remote attackers can then exploit the vulnerability to modify memory or crash processes.
We have already fixed the vulnerability in the following version:
Media Streaming Add-on 500.1.1 and later
QNAP Photo Station Externally Controlled Reference Vulnerability
critical
activeCISA KEVCVE-2022-27593
Certain QNAP NAS running Photo Station with internet exposure contain an externally controlled reference to a resource vulnerability which can allow an attacker to modify system files. This vulnerability was observed being utilized in a Deadbolt ransomware campaign. Known ransomware use: Known.
QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files. Known ransomware use: Known.
QNAP Photo Station Improper Access Control Vulnerability
critical
activeCISA KEVCVE-2019-7192
QNAP NAS devices running Photo Station contain an improper access control vulnerability allowing remote attackers to gain unauthorized access to the system. Known ransomware use: Known.
QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files. Known ransomware use: Known.
QNAP NAS File Station Cross-Site Scripting Vulnerability
critical
activeCISA KEVCVE-2018-19953
A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. Known ransomware use: Known.
QNAP NAS File Station Cross-Site Scripting Vulnerability
critical
activeCISA KEVCVE-2018-19943
A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. Known ransomware use: Known.
QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device. Known ransomware use: Known.
A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers can then exploit the vulnerability to gain access to the system.
We have already fixed the vulnerability in the following version:
QVR Pro 2.7.4.14 and later
qvr pro
CRITICALCVE-2026-22898
Watch
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 0.4% EPSS.
media streaming add-on vulnerability (CVE-2025-59383)
A buffer overflow vulnerability has been reported to affect Media Streaming Add-On. The remote attackers can then exploit the vulnerability to modify memory or crash processes.
We have already fixed the vulnerability in the following version:
Media Streaming Add-on 500.1.1 and later
media streaming add-on
LOWCVE-2025-59383
Watch
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 0.1% EPSS.
QNAP Photo Station Externally Controlled Reference Vulnerability
Certain QNAP NAS running Photo Station with internet exposure contain an externally controlled reference to a resource vulnerability which can allow an attacker to modify system files. This vulnerability was observed being utilized in a Deadbolt ransomware campaign. Known ransomware use: Known.
Photo Station
criticalCVE-2022-27593
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 93.1% EPSS.
QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files. Known ransomware use: Known.
Photo Station
criticalCVE-2019-7195
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 94.1% EPSS.
QNAP Photo Station Improper Access Control Vulnerability
QNAP NAS devices running Photo Station contain an improper access control vulnerability allowing remote attackers to gain unauthorized access to the system. Known ransomware use: Known.
Photo Station
criticalCVE-2019-7192
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 94.3% EPSS.
QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files. Known ransomware use: Known.
Photo Station
criticalCVE-2019-7194
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 93.9% EPSS.
QNAP NAS File Station Cross-Site Scripting Vulnerability
A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. Known ransomware use: Known.
Network Attached Storage (NAS)
criticalCVE-2018-19953
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 31.5% EPSS.
QNAP NAS File Station Cross-Site Scripting Vulnerability
A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. Known ransomware use: Known.
Network Attached Storage (NAS)
criticalCVE-2018-19943
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 7.0% EPSS.
QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device. Known ransomware use: Known.
Network Attached Storage (NAS)
criticalCVE-2021-28799
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 90.8% EPSS.
It is the QNAP-specific view inside ITECS Threat Radar, built to track recent advisories, incidents, and watch items that may affect Dallas-area business operations.
How should teams use the QNAP watch page?
Use it to confirm whether current QNAP issues overlap with your environment, prioritize remediation, and decide whether you need an assessment, managed security follow-through, or vendor-specific hardening work.
Can ITECS help respond to QNAP security issues?
Yes. ITECS can help map QNAP advisories against your systems, validate affected services, prioritize remediation, and connect the issue to broader managed cybersecurity or managed IT workflows.