CVE-2026-41539: QTS, QuTS hero
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to bypass security mechanisms or read application data.
We have already fixed the vulnerability in the following versions: QTS 5.2.9.3492 build 20260507 and later QuTS hero h5.2.9.3499 build 20260514 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3500 build 20260520 and later
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41539?
The severity of CVE-2026-41539 is rated high with a score of 8.7.
How do I fix CVE-2026-41539?
To fix CVE-2026-41539, update to QTS version 5.2.9.3492 or later and QuTS hero version h5.2.9.3499 or later.
What type of attack is CVE-2026-41539 associated with?
CVE-2026-41539 is associated with a cross-site scripting (XSS) attack.
What is the impact of CVE-2026-41539?
The impact of CVE-2026-41539 allows remote attackers to bypass security mechanisms or read application data.
Which versions of QNAP OS are affected by CVE-2026-41539?
CVE-2026-41539 affects several versions of QNAP QTS and QuTS hero prior to the specified fixed versions.