CyberMax
Home › Exploited CVEs

QNAP known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 11 QNAP CVEs as exploited in the wild. 0 were added in the last 12 months (latest 2023-12-21), and 9 are known to be used in ransomware campaigns.

QNAP CVEs added to CISA KEV per year
2022: 102022102023: 120231

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected QNAP products

Photo Station (4), Network Attached Storage (NAS) (4), VioStor NVR (1), QTS (1), QNAP Network-Attached Storage (NAS) (1).

All QNAP CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2023-47565VioStor NVRVioStor NVR OS Command Injection2023-12-212024-01-1173.3%–
CVE-2022-27593Photo StationPhoto Station Externally Controlled Reference2022-09-082022-09-2987.9%Yes
CVE-2019-7195Photo StationPhoto Station Path Traversal2022-06-082022-06-2289.7%Yes
CVE-2019-7194Photo StationPhoto Station Path Traversal2022-06-082022-06-2283.1%Yes
CVE-2019-7193QTSQTS Improper Input Validation2022-06-082022-06-2214.4%Yes
CVE-2019-7192Photo StationPhoto Station Improper Access Control2022-06-082022-06-2288.1%Yes
CVE-2018-19953Network Attached Storage (NAS)NAS File Station Cross-Site Scripting2022-05-242022-06-1428.8%Yes
CVE-2018-19949Network Attached Storage (NAS)NAS File Station Command Injection2022-05-242022-06-1428.4%Yes
CVE-2018-19943Network Attached Storage (NAS)NAS File Station Cross-Site Scripting2022-05-242022-06-1421.5%Yes
CVE-2020-2509QNAP Network-Attached Storage (NAS)Network-Attached Storage (NAS) Command Injection2022-04-112022-05-0234.0%–
CVE-2021-28799Network Attached Storage (NAS)NAS Improper Authorization2022-03-312022-04-2178.2%Yes
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors