Review reviewHigh

CVE-2026-22893

QNAP Systems Inc. QTS, QuTS hero, qts

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build 20260214 and later QuTS hero h5.2.9.3410 build 20260214 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3459 build 20260409 and later

CVSS
8.6
EPSS
1.09%
62.0% percentile
CISA KEV
Not listed
Published
2026.06.10
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability1.09%
Technical severityCVSS 8.6

Vulnerability overview

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build 20260214 and later QuTS hero h5.2.9.3410 build 20260214 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3459 build 20260409 and later

Affected product and versions

Product
QNAP Systems Inc. QTS, QuTS hero, qts
Affected versions
>= 5.2.0 < 5.2.9.3410 build 20260214, >= h5.2.0 < h5.2.9.3410 build 20260214, >= h5.3.0 < h5.3.4.3500 build 20260520, >= ? < h6.0.0.3459 build 20260409, >= 5.2.0.2737 < 5.2.9.3410, >= h5.2.0.2737 < h5.2.9.3410, >= h5.3.0.3115 < h5.3.4.3500, >= h6.0.0.3324 < h6.0.0.3459
Fixed versions
5.2.9.3410, h5.2.9.3410, h5.3.4.3500, h6.0.0.3459

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that QNAP Systems Inc. QTS, QuTS hero, qts and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE
CWE-78
CVE-2026-22893 — QNAP Systems Inc. QTS, QuTS hero, qts | SECUFOCUS NOW