CVE-2026-24716: QTS, QuTS hero
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions: QTS 5.2.9.3492 build 20260507 and later QuTS hero h5.2.9.3499 build 20260514 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3459 build 20260409 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24716?
The severity of CVE-2026-24716 is classified as medium with a CVSS score of 5.1.
How do I fix CVE-2026-24716?
You can fix CVE-2026-24716 by updating to QTS 5.2.9.3492 build 20260507 or later, or QuTS hero versions mentioned in the vulnerability description.
What systems are affected by CVE-2026-24716?
CVE-2026-24716 affects several versions of QNAP QTS and QNAP QuTS hero operating systems.
What can an attacker do by exploiting CVE-2026-24716?
An attacker with an administrator account can exploit CVE-2026-24716 to launch a denial-of-service (DoS) attack.
What type of vulnerability is CVE-2026-24716?
CVE-2026-24716 is classified as a null pointer dereference vulnerability.