QNAP threat watch

QNAP CVE coverage for NAS systems, backup workflows, storage services, and exposed SMB infrastructure.

Vendor watch hub

What this page covers

The QNAPwatch hub is a vendor-specific view inside ITECS MSP Threat Radar. We pull the latest security advisories, incidents, and known-exploited CVEs directly from the official feeds below, score each one for MSP relevance, and surface what's most likely to need attention this week.

  • Confirm whether recent QNAP activity overlaps with your environment.
  • Prioritize advisories by MSP-relevance score, severity, and status.
  • Turn the signal into an assessment, briefing, or managed-service engagement with ITECS.

At a glance

Tracked

13

Active

11

Featured

12

Unique CVEs

13

Most recent entry

Mar 20, 2026, 12:16 PM

Feed refreshes daily · 5:15 a.m. Central

Sources·CISA KEV and NVD (product vendor coverage)

"Most recent entry" is the newest item the upstream feed has published — not our sync time.

Watch items

Recent QNAP watch items

Showing the 13 most recent items, newest first. Each row links to the official advisory.

13 rows · sorted newest first

Operations view

qvr pro vulnerability (CVE-2026-22898)

CRITICAL
watchNVDCVE-2026-22898

A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers can then exploit the vulnerability to gain access to the system. We have already fixed the vulnerability in the following version: QVR Pro 2.7.4.14 and later

Mar 20, 2026, 12:16 PMOfficial source

media streaming add-on vulnerability (CVE-2025-59383)

LOW
watchNVDCVE-2025-59383

A buffer overflow vulnerability has been reported to affect Media Streaming Add-On. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Media Streaming Add-on 500.1.1 and later

Mar 20, 2026, 12:16 PMOfficial source

QNAP VioStor NVR OS Command Injection Vulnerability

critical
activeCISA KEVCVE-2023-47565

QNAP VioStar NVR contains an OS command injection vulnerability that allows authenticated users to execute commands via a network.

Dec 20, 2023, 6:00 PMOfficial source

QNAP Photo Station Externally Controlled Reference Vulnerability

critical
activeCISA KEVCVE-2022-27593

Certain QNAP NAS running Photo Station with internet exposure contain an externally controlled reference to a resource vulnerability which can allow an attacker to modify system files. This vulnerability was observed being utilized in a Deadbolt ransomware campaign. Known ransomware use: Known.

Sep 7, 2022, 7:00 PMOfficial source

QNAP Photo Station Path Traversal Vulnerability

critical
activeCISA KEVCVE-2019-7195

QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files. Known ransomware use: Known.

Jun 7, 2022, 7:00 PMOfficial source

QNAP Photo Station Improper Access Control Vulnerability

critical
activeCISA KEVCVE-2019-7192

QNAP NAS devices running Photo Station contain an improper access control vulnerability allowing remote attackers to gain unauthorized access to the system. Known ransomware use: Known.

Jun 7, 2022, 7:00 PMOfficial source

QNAP Photo Station Path Traversal Vulnerability

critical
activeCISA KEVCVE-2019-7194

QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files. Known ransomware use: Known.

Jun 7, 2022, 7:00 PMOfficial source

QNAP QTS Improper Input Validation Vulnerability

critical
activeCISA KEVCVE-2019-7193

QNAP QTS contains an improper input validation vulnerability allowing remote attackers to inject code on the system. Known ransomware use: Known.

Jun 7, 2022, 7:00 PMOfficial source

QNAP NAS File Station Cross-Site Scripting Vulnerability

critical
activeCISA KEVCVE-2018-19953

A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. Known ransomware use: Known.

May 23, 2022, 7:00 PMOfficial source

QNAP NAS File Station Command Injection Vulnerability

critical
activeCISA KEVCVE-2018-19949

A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands. Known ransomware use: Known.

May 23, 2022, 7:00 PMOfficial source

QNAP NAS File Station Cross-Site Scripting Vulnerability

critical
activeCISA KEVCVE-2018-19943

A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. Known ransomware use: Known.

May 23, 2022, 7:00 PMOfficial source

QNAP Network-Attached Storage (NAS) Command Injection Vulnerability

critical
activeCISA KEVCVE-2020-2509

QNAP NAS devices contain a command injection vulnerability which could allow attackers to perform remote code execution.

Apr 10, 2022, 7:00 PMOfficial source

QNAP NAS Improper Authorization Vulnerability

critical
activeCISA KEVCVE-2021-28799

QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device. Known ransomware use: Known.

Mar 30, 2022, 7:00 PMOfficial source

Related vendors

Other security vendors in the radar

Vendor watch FAQ

Common questions

What is the QNAP threat watch page?

It is the QNAP-specific view inside ITECS Threat Radar, built to track recent advisories, incidents, and watch items that may affect Dallas-area business operations.

How should teams use the QNAP watch page?

Use it to confirm whether current QNAP issues overlap with your environment, prioritize remediation, and decide whether you need an assessment, managed security follow-through, or vendor-specific hardening work.

Can ITECS help respond to QNAP security issues?

Yes. ITECS can help map QNAP advisories against your systems, validate affected services, prioritize remediation, and connect the issue to broader managed cybersecurity or managed IT workflows.