QNAP QTS

QNAP · current 5.2.10.3577

Are you QNAP? Claim this page

The current version of QNAP QTS is 5.2.10.3577 (as of 06/08/2026). patchletter checks the official source daily and emails you new releases.

Actively exploited vulnerabilities

The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. What CISA does not carry does not appear in this list — even where it is being exploited.

  • CVE-2021-28799QNAP NAS Improper Authorization VulnerabilityRansomware

    9.8 critical · over the network, without login · CISA deadline was 21 Apr 22

  • CVE-2018-19949QNAP NAS File Station Command Injection VulnerabilityRansomware

    9.8 critical · over the network, without login · CISA deadline was 14 Jun 22

  • CVE-2019-7193QNAP QTS Improper Input Validation VulnerabilityRansomware

    9.8 critical · over the network, without login · CISA deadline was 22 Jun 22

  • CVE-2018-19953QNAP NAS File Station Cross-Site Scripting VulnerabilityRansomware

    6.1 medium · over the network, without login, needs user action · CISA deadline was 14 Jun 22

  • CVE-2018-19943QNAP NAS File Station Cross-Site Scripting VulnerabilityRansomware

    5.4 medium · over the network, with a basic account, needs user action · CISA deadline was 14 Jun 22

  • CVE-2020-2509QNAP Network-Attached Storage (NAS) Command Injection Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 2 May 22

Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.

QNAP QTS at a glance

QTS is the operating system on QNAP NAS devices — file, backup and app services in a web-managed appliance, widespread in SMBs and homelabs. QNAP ships QTS updates plus security advisories; as an internet-adjacent storage device that has been heavily targeted by ransomware, updates are time-critical.

For admins the rules are sharpened: never expose the NAS admin interface to the open internet, disable default accounts, enable two-factor, and apply security updates promptly. Back up the configuration before major QTS jumps and check app compatibility. Snapshots and off-box, immutable backups are the core defense against the ransomware campaigns that specifically hit QNAP devices. Subscribe to QNAP's security advisories; patchletter flags new QTS builds so critical fixes aren't missed.

Support cycles (endoflife.date)

CycleLatest versionStatus
5.2 (LTS)LTS5.2.10.3577EOL 31 Aug 29
4.4.1–End of Life
4.3.6–End of Life
4.3.3–End of Life
4.2.6–End of Life

Version history & changelog · as detected by patchletter

VersionChannelDateNotes
5.2.10.3577STABLE06/08/2026Release notes →
5.2.10.3568STABLE26/07/2026Release notes →
5.2.9.3499STABLE26/07/2026Release notes →
5.2.9.3492STABLE26/07/2026Release notes →
5.2.9.3451STABLE26/07/2026Release notes →
5.2.9.3410STABLE26/07/2026Release notes →

Frequently asked questions

What is the latest version of QNAP QTS?
QNAP QTS 5.2.10.3577, released 06/08/2026. patchletter checks the vendor's official source daily for new releases.
Where can I find the QNAP QTS release notes?
The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
How do I get notified about new QNAP QTS updates?
Tick QNAP QTS off in the catalogue and leave your address. From then on new versions go out by email — one at a time, or bundled in the daily or weekly digest.

An email as soon as a new QNAP QTS version ships

We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The update email is free and ends with one click. Alerts about vulnerabilities and end of support are part of patchletter Pro.

Embed this badge

The badge shows the current QNAP QTS version and keeps it up to date. Anyone may embed it, no account needed.

QNAP QTS badge
[![QNAP QTS](https://patchletter.com/badge/qnap-qts.svg)](https://patchletter.com/en/software/qnap-qts)
https://patchletter.com/badge/qnap-qts.svg

Also available: ?v=eol (end of support) and ?v=cve (actively exploited).

Related tools in NAS & Storage