vulnerability

QNAP QTS: CVE-2025-66276: Vulnerability in legacy QTS with NFS service enabled

Severity
9
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:N)
Published
Jan 17, 2026
Added
Jan 30, 2026
Modified
Jan 30, 2026

Description

A vulnerability has been reported to affect certain legacy QTS environments utilizing the NFS (Network File System) service. If exploited, the vulnerability allows attackers to perform actions and potentially gain access due to the misconfiguration of NFS settings. We have already fixed the vulnerability in the following version:

Solution

qnap-qts-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.