CVE-2024-14026: QNAP QTS

High severity, CVSS 7.8. EPSS: 0.6% chance of exploitation in the next 30 days.

A command injection vulnerability has been reported to affect several QNAP operating system versions. If an attacker gains local network access who have also gained a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.3.3006 build 20250108 and later QuTS hero h5.1.9.2954 build 20241120 and later QuTS hero h5.2.3.3006 build 20250108 and later

Affected products

  • QNAP QTS: version 5.1.0.2348 only; version 5.1.0.2399 only; version 5.1.0.2418 only; version 5.1.0.2444 only; version 5.1.0.2466 only; version 5.1.1.2491 only; …
  • QNAP Quts Hero: version h5.1.0.2409 only; version h5.1.0.2424 only; version h5.1.0.2453 only; version h5.1.0.2466 only; version h5.1.1.2488 only; version h5.1.2.2534 only; …

Published 2026-03-11. Last modified 2026-06-17.