We have already fixed the vulnerability in the following versions:
QTS 5.2.9.3492 build 20260507 and later
QuTS hero h5.2.9.3499 build 20260514 and later
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
We have already fixed the vulnerability in the following versions: QTS 5.2.9.3492 build 20260507 and later QuTS hero h5.2.9.3499 build 20260514 and later
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-26-23 |
|
Mon, 15 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qnap
Qnap qts Qnap quts Hero |
|
| CPEs | cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:* cpe:2.3:o:qnap:quts_hero:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Qnap
Qnap qts Qnap quts Hero |
|
| Metrics |
cvssV3_1
|
Wed, 10 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qnap Systems
Qnap Systems qts Qnap Systems quts Hero |
|
| Vendors & Products |
Qnap Systems
Qnap Systems qts Qnap Systems quts Hero |
Wed, 10 Jun 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3492 build 20260507 and later QuTS hero h5.2.9.3499 build 20260514 and later | |
| Title | QTS, QuTS hero | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: qnap
Published:
Updated: 2026-06-11T03:55:22.349Z
Reserved: 2026-01-26T06:41:35.897Z
Link: CVE-2026-24719
Updated: 2026-06-10T15:47:00.937Z
Status : Analyzed
Published: 2026-06-10T04:17:17.007
Modified: 2026-06-15T18:33:24.003
Link: CVE-2026-24719
No data.
OpenCVE Enrichment
Updated: 2026-06-10T04:30:06Z