Exploited CVEs / By vendor / QNAP

QNAP vulnerabilities actively exploited

11 QNAP CVEs on the CISA Known Exploited Vulnerabilities catalog, newest first. Refreshed daily.

Every CVE below is confirmed exploited in the wild, not just theoretically severe. The newest addition is CVE-2023-47565 (VioStor NVR, added 2023-12-21). 9 of the 11 are used in ransomware campaigns. New CISA KEV entries appear here the day they are cataloged; the freshest across all vendors are on exploited this week.

11 exploited CVEs9 ransomware-linked
Senserva AI Opinion and rich prompt for QNAP exploited CVEs

Copy this prompt into Claude, ChatGPT, or Copilot. The facts are included, sourced from this page.

Photo Station: 4 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2022-27593Photo Station2022-09-08ransomware, CVSS 9.1, EPSS 88%
CVE-2019-7192Photo Station2022-06-08ransomware, CVSS 9.8, EPSS 88%
CVE-2019-7194Photo Station2022-06-08ransomware, CVSS 9.8, EPSS 83%
CVE-2019-7195Photo Station2022-06-08ransomware, CVSS 9.8, EPSS 90%

Network Attached Storage (NAS): 4 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2018-19943Network Attached Storage (NAS)2022-05-24ransomware, CVSS 5.4, EPSS 18%
CVE-2018-19949Network Attached Storage (NAS)2022-05-24ransomware, CVSS 9.8, EPSS 24%
CVE-2018-19953Network Attached Storage (NAS)2022-05-24ransomware, CVSS 6.1, EPSS 24%
CVE-2021-28799Network Attached Storage (NAS)2022-03-31ransomware, CVSS 9.8, EPSS 78%

Other QNAP products

CVEProductAdded to KEVSignals
CVE-2023-47565VioStor NVR2023-12-21CVSS 8.8, EPSS 73%
CVE-2019-7193QTS2022-06-08ransomware, CVSS 9.8, EPSS 14%
CVE-2020-2509QNAP Network-Attached Storage (NAS)2022-04-11CVSS 9.8, EPSS 33%

Common questions about exploited QNAP CVEs

Which QNAP vulnerabilities are actively exploited?

As of August 2026, 11 QNAP CVEs are on the CISA Known Exploited Vulnerabilities catalog, meaning exploitation in the wild is confirmed. The most-listed products are Photo Station (4), Network Attached Storage (NAS) (4). 9 are linked to ransomware campaigns.

What is the newest exploited QNAP CVE?

CVE-2023-47565, affecting VioStor NVR, added to the CISA KEV catalog on 2023-12-21. This page refreshes daily, so the newest entry is always first in the table.

How urgent are these QNAP CVEs?

KEV listing is the strongest fix-first signal there is: it means confirmed exploitation, not a prediction. Patch these ahead of higher-CVSS issues that nobody is exploiting. Check the vendor advisory (linked below) for fixed versions and workarounds.

Can I ask my own AI about exploited QNAP CVEs?

Yes. This page includes a free copy-paste AI prompt carrying the newest QNAP KEV entries, with CVSS, EPSS, and ransomware context, into Claude, ChatGPT, or Copilot. The data is refreshed twice a day (5 AM and 3 PM US Central).

All vendors, searchable with due dates and CSV export: the exploited-CVE tracker. Every vendor with a page: exploited by vendor.

Most searched on Senserva right now

New to a term on this page? CVE, KB, KEV, CVSS, and EPSS are each explained once, on the Senserva security lexicon. Reference: Microsoft CVE and vulnerability management and the Microsoft patching guide.
Provided as is, without warranty; verify against the vendor advisory before acting. Data notice and terms.