Synology, QNAP
This page is grounded in the current research notes and official-source dataset, then organized into a cleaner public landing page.
Device type
NAS is one of the strongest categories because Synology and QNAP publish structured advisories with fixed versions or clear interim mitigation guidance.
This page is grounded in the current research notes and official-source dataset, then organized into a cleaner public landing page.
| Vendor | Update | Fixed version(s) | Published | Source |
|---|---|---|---|---|
| Synology DSM / Synology MailPlus Server | Synology-SA-26:11 MailPlus Server security update Synology published a Critical MailPlus Server package advisory for DSM with explicit fixed package versions across current DSM branches. | MailPlus Server 4.0.1-31663+ for DSM 7.3 MailPlus Server 4.0.1-21663+ for DSM 7.2.2 and 7.2.1 | 2026-06-26 | Official source ↗ |
| QNAP QTS 5.2.7 / QuTS hero h5.2.8 / QuTS cloud c5.2.8 / QVP 2.7.1 | QSA-26-10 vulnerabilities in QTS, QuTS hero, QuTS cloud, and QVP QNAP published a broad Important advisory spanning NAS and appliance software lines, with explicit fixed releases despite the bulletin covering fourteen vulnerabilities and several remote attack paths. | QTS 5.2.9.3499 QuTS hero h5.2.9 QuTS cloud C5.2.9 QVP 2.8.0 | 2026-06-17 | Official source ↗ |
| Synology DSM / Synology Chat Server | Synology-SA-26:10 Chat Server security update Synology published an Important Chat Server package advisory for DSM with three named vulnerabilities and one clear fixed package build across current supported DSM branches. | Synology Chat Server 2.4.5-22148+ for DSM 7.3 Synology Chat Server 2.4.5-22148+ for DSM 7.2.2 and 7.2.1 | 2026-05-26 | Official source ↗ |
| QNAP QTS / QuTS hero / QuTScloud Linux kernel | QSA-26-17 Dirty Frag Linux kernel privilege-escalation advisory QNAP says the Linux kernel "Dirty Frag" privilege-escalation flaw affects broad current NAS operating-system lines and, after initially publishing mitigations, marked QSA-26-17 resolved on May 25, 2026 with guidance to install the latest firmware. | Resolved on 2026-05-25; install the latest firmware. QNAP does not list branch-specific minimum fixed builds in the advisory. | 2026-05-11 | Official source ↗ |
| Synology DSM | Synology-SA-26:06 DSM security update Synology published a broad DSM advisory covering 11 vulnerabilities and gave explicit fixed releases across current supported DSM branches. | DSM 7.3.2-86009-2+ DSM 7.2.2-72806-7+ DSM 7.2.1-69057-10+ | 2026-04-15 | Official source ↗ |
| Synology DSM / Mail Station | Synology-SA-26:04 Mail Station security update Synology published a Mail Station package advisory for DSM with a clear fixed package build across current DSM branches. | Mail Station 30000001.3.19-20332+ for DSM 7.3 Mail Station 30000001.3.19-20332+ for DSM 7.2.2 and 7.2.1 | 2026-03-31 | Official source ↗ |
| Synology DSM / GNU Inetutils telnetd | Synology-SA-26:03 DSM critical security update Synology disclosed a critical DSM update for GNU Inetutils telnetd with explicit fixed releases for supported DSM branches. | DSM 7.3.2-86009-3+ DSM 7.2.2-72806-8+ DSM 7.2.1-69057-11+ | 2026-03-19 | Official source ↗ |
| QNAP QTS / QuTS hero | QSA-25-50 Multiple Vulnerabilities in QTS and QuTS hero QNAP published a broad QTS and QuTS hero advisory covering null-pointer dereference, buffer overflow, out-of-bounds read, format string, and resource exhaustion issues across current NAS operating system branches. | QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.1.3250 build 20250912 and later | 2026-01-03 | Official source ↗ |
| Synology DSM / Storage Manager | Synology-SA-26:01 Storage Manager Synology released a Storage Manager package security update for DSM 7.3 and DSM 7.2.x after disclosing a local information exposure issue. | 1.0.1-1100 or above | 2026-02-09 | Official source ↗ |
| Synology DSM SSO | Synology-SA-25:14 DSM (PWN2OWN 2025) auth-bypass update Synology published a PWN2OWN-linked DSM advisory for an SSO authentication-bypass issue, with explicit fixed releases and a clear note that DSM 7.2.1 is not affected. | DSM 7.3.1-86003-1+ DSM 7.2.2-72806-5+ DSM 7.2.1 not affected | 2025-11-19 | Official source ↗ |
| QNAP QTS / QuTS hero | QSA-25-45 Multiple Vulnerabilities in QTS and QuTS hero (PWN2OWN 2025) QNAP disclosed PWN2OWN-linked QTS and QuTS hero vulnerabilities including command injection, SQL injection, null-pointer dereference, and authentication bypass, with fixed builds for both 5.2 and 5.3-era NAS software tracks. | QTS 5.2.7.3297 build 20251024 and later QuTS hero h5.2.7.3297 build 20251024 and later QuTS hero h5.3.1.3292 build 20251024 and later | 2025-11-08 | Official source ↗ |