Product of QNAP
Network Attached Storage (NAS)
As of , 4 QNAP Network Attached Storage (NAS) vulnerabilities are on CISA's list of exploited vulnerabilities, 4 of them used in ransomware campaigns; 0 were added in 2026. Patch first: CVE-2021-28799.
Patch first
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1 | CVE-2021-28799NAS Improper Authorization | QNAP Network Attached Storage (NAS) | Patch this weekRansomware use; EPSS 0.78 | 0.78 | ||
| 2 | CVE-2018-19949NAS File Station Command Injection | QNAP Network Attached Storage (NAS) | Patch this weekRansomware use | 0.28 | ||
| 3 | CVE-2018-19953NAS File Station Cross-Site Scripting | QNAP Network Attached Storage (NAS) | Patch this weekRansomware use | 0.29 | ||
| 4 | CVE-2018-19943NAS File Station Cross-Site Scripting | QNAP Network Attached Storage (NAS) | Patch this weekRansomware use | 0.21 |
Added each year
Show the numbers
| Period | entries added |
|---|---|
| 2022 | 4 |
| 2023 | none |
| 2024 | none |
| 2025 | none |
| 2026 | none |