PT-2026-47687 · Qnap · Qts+1

CVE-2026-41539

·

Published

2026-06-09

·

Updated

2026-06-30

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions QTS versions prior to 5.2.9.3492 build 20260507 QuTS hero versions prior to h5.2.9.3499 build 20260514 QuTS hero versions prior to h5.3.4.3500 build 20260520 QuTS hero versions prior to h6.0.0.3500 build 20260520
Description A cross-site scripting (XSS) issue allows remote attackers to bypass security mechanisms or read application data. Cross-site scripting is a flaw where malicious scripts are injected into trusted websites.
Recommendations Update to QTS 5.2.9.3492 build 20260507 or later. Update to QuTS hero h5.2.9.3499 build 20260514 or later. Update to QuTS hero h5.3.4.3500 build 20260520 or later. Update to QuTS hero h6.0.0.3500 build 20260520 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41539

Affected Products

Qts
Quts Hero