High severity8.1NVD Advisory· Published Jun 10, 2026· Updated Jun 12, 2026
CVE-2026-26239
CVE-2026-26239
Description
A buffer overflow vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes.
We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5208 and later
Affected products
2cpe:2.3:a:qnap:file_station:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:qnap:file_station:*:*:*:*:*:*:*:*range: >=5.5.6.4691,<5.5.6.5208
- (no CPE)range: <5.5.6.5208
Patches
Vulnerability mechanics
References
1- www.qnap.com/en/security-advisory/qsa-26-37nvdBroken Link
News mentions
1- QNAP Patches Multiple Injection Vulnerabilities Leads to Arbitrary Command ExecutionCyber Security News · Jun 22, 2026