Product of QNAP

Network Attached Storage (NAS)

As of , 4 QNAP Network Attached Storage (NAS) vulnerabilities are on CISA's list of exploited vulnerabilities, 4 of them used in ransomware campaigns; 0 were added in 2026. Patch first: CVE-2021-28799.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2021-28799NAS Improper AuthorizationQNAP Network Attached Storage (NAS)Patch this weekRansomware use; EPSS 0.780.78
2CVE-2018-19949NAS File Station Command InjectionQNAP Network Attached Storage (NAS)Patch this weekRansomware use0.28
3CVE-2018-19953NAS File Station Cross-Site ScriptingQNAP Network Attached Storage (NAS)Patch this weekRansomware use0.29
4CVE-2018-19943NAS File Station Cross-Site ScriptingQNAP Network Attached Storage (NAS)Patch this weekRansomware use0.21

Added each year

12342022: 4420222023: nonenone20232024: nonenone20242025: nonenone20252026: nonenone2026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20224
2023none
2024none
2025none
2026none

Used in ransomware