A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3492 build 20260507 and later QuTS hero h5.2.9.3499 build 20260514 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3459 build 20260409 and later
Update QNAP Systems Inc./QTS to 5.2.9.3492 build 20260507; QNAP Systems Inc./QuTS hero to h5.2.9.3499 build 20260514 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanQTS, QuTS hero affects QNAP Systems Inc./QTS (generic), QNAP Systems Inc./QuTS hero (generic). Severity is high. A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3492 build 20260507 and later QuTS hero h5.2.9.3499 build 20260514 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3459 build 20260409 and later
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| QNAP Systems Inc./QTSgeneric |
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3492 build 20260507 and later QuTS hero h5.2.9.3499 build 20260514 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3459 build 20260409 and later
Update QNAP Systems Inc./QTS to 5.2.9.3492 build 20260507; QNAP Systems Inc./QuTS hero to h5.2.9.3499 build 20260514 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanQTS, QuTS hero affects QNAP Systems Inc./QTS (generic), QNAP Systems Inc./QuTS hero (generic). Severity is high. A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3492 build 20260507 and later QuTS hero h5.2.9.3499 build 20260514 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3459 build 20260409 and later
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| QNAP Systems Inc./QTSgeneric |
| >=5.2.0 <5.2.9.3492 build 20260507 |
| 5.2.9.3492 build 20260507 |
| QNAP Systems Inc./QuTS herogeneric | >=h5.2.0 <h5.2.9.3499 build 20260514 || >=h5.3.0 <h5.3.4.3500 build 20260520 || >=? <h6.0.0.3459 build 20260409 | h5.2.9.3499 build 20260514, h5.3.4.3500 build 20260520, h6.0.0.3459 build 20260409 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| >=5.2.0 <5.2.9.3492 build 20260507 |
| 5.2.9.3492 build 20260507 |
| QNAP Systems Inc./QuTS herogeneric | >=h5.2.0 <h5.2.9.3499 build 20260514 || >=h5.3.0 <h5.3.4.3500 build 20260520 || >=? <h6.0.0.3459 build 20260409 | h5.2.9.3499 build 20260514, h5.3.4.3500 build 20260520, h6.0.0.3459 build 20260409 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard