CVE-2026-41539

MEDIUM

QNAP Systems - QTS, QuTS Hero

Title source: rule
STIX 2.1

Description

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3492 build 20260507 and later QuTS hero h5.2.9.3499 build 20260514 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3500 build 20260520 and later

References (1)

Core 1

Scores

CVSS v3 6.1
EPSS 0.0019
EPSS Percentile 9.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (50)
qnap/qts 5.2.0.2737 build_20240417
qnap/qts 5.2.0.2744 build_20240424
qnap/qts 5.2.0.2782 build_20240601
qnap/qts 5.2.0.2802 build_20240620
qnap/qts 5.2.0.2823 build_20240711
qnap/qts 5.2.0.2851 build_20240808
qnap/qts 5.2.0.2860 build_20240817
qnap/qts 5.2.1.2930 build_20241025
qnap/qts 5.2.2.2950 build_20241114
qnap/qts 5.2.3.3006 build_20250108
... and 40 more
Published Jun 09, 2026
Tracked Since Jun 09, 2026