
The security advisory, identified as QSA-26-10, was released by QNAP on June 17, 2026, while a related security notice was published on June 24, 2026. The , successful exploitation could lead to denial-of-service conditions, information disclosure, elevation of privileges, remote code execution, and security restriction bypass.
One of the most notable flaws, CVE-2025-59382, is a URL injection or cause CGI service crashes through excessively long filenames during file upload operations.
Access Control and Resource Consumption Issues
Among the other QNAP NAS vulnerabilities, CVE-2026-24724 involves associated with CVE-2025-59382 and other vulnerabilities in QNAP NAS systems, administrators are advised to update their devices to the latest firmware versions. QNAP recommends regularly checking for software updates and applying vendor-issued security patches to reduce exposure to newly discovered threats.
SOCIAL SHARE CARD GENERATOR