CVE-2026-24719: QTS, QuTS hero
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3492 build 20260507 and later QuTS hero h5.2.9.3499 build 20260514 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24719?
The severity of CVE-2026-24719 is rated as high with a CVSS score of 8.6.
How do I fix CVE-2026-24719?
To fix CVE-2026-24719, upgrade to QTS version 5.2.9.3492 build 20260507 or later, or QuTS hero version h5.2.9.3499 build 20260514 or later.
What type of vulnerability is CVE-2026-24719?
CVE-2026-24719 is identified as a command injection vulnerability affecting QNAP operating systems.
Who is affected by CVE-2026-24719?
Users of QNAP QTS and QNAP QuTS hero operating systems with vulnerable versions are at risk for CVE-2026-24719.
Can CVE-2026-24719 be exploited remotely?
Yes, CVE-2026-24719 can be exploited remotely if an attacker gains an administrator account on the affected system.