Published on: 12 May 2026
QNAP has published a security advisory to address multiple vulnerabilities in QNAP products. The list of patches can be found at:
https://www.qnap.com/go/security-advisory/qsa-26-17
Reports indicated that proof-of-concept (PoC) exploit code is available for an elevation of privilege vulnerability (CVE-2026-43284). System administrators are advised to take immediate action to patch your affected systems to mitigate the elevated risk of cyber attacks.
For detailed information of the affected systems, please refer to the corresponding security advisory at vendor's website.
Successful exploitation of the vulnerabilities could lead to elevation of privilege on an affected system.
System administrators of affected systems should follow the recommendations provided by the vendor and take immediate actions to mitigate the risk.