High severity7.2NVD Advisory· Published Jun 10, 2026· Updated Jun 15, 2026
CVE-2026-22893
CVE-2026-22893
Description
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands.
We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build 20260214 and later QuTS hero h5.2.9.3410 build 20260214 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3459 build 20260409 and later
Affected products
4cpe:2.3:o:qnap:quts_hero:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:qnap:quts_hero:*:*:*:*:*:*:*:*range: >=h5.2.0.2737,<h5.2.9.3410
- (no CPE)range: <h5.2.9.3410 build 20260214 (for the 5.2.x line); <h5.3.4.3500 build 20260520 (for the 5.3.x line); <h6.0.0.3459 build 20260409 (for the 6.0.x line)
Patches
Vulnerability mechanics
References
1- www.qnap.com/en/security-advisory/qsa-26-10nvdVendor AdvisoryBroken Link
News mentions
4- ⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and MoreThe Hacker News · Jul 6, 2026
- QNAP Patches Multiple Injection Vulnerabilities Leads to Arbitrary Command ExecutionCyber Security News · Jun 22, 2026
- QNAP QTS: Critical Command Injection and XSS Flaws Disclosed in BatchVypr Intelligence · Jun 10, 2026
- QNAP QuTS hero: 12 Vulnerabilities Disclosed, Including Command Injection and XSSVypr Intelligence · Jun 10, 2026