CVE-2025-66276: QNAP QTS

Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.

QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250913 and later

Affected products

  • QNAP QTS: from 4.3.0, before 5.2.7.3256 (fixed in 5.2.7.3256)

Published 2026-06-10. Last modified 2026-07-23.