CVE-2026-22898Disclosure(qnap / qvr_pro)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch qnap qvr_pro systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers can then exploit the vulnerability to gain access to the system. We have already fixed the vulnerability in the following version: QVR Pro 2.7.4.14 and later

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • qvr_pro

Threat summary

  • Patch or workaround signal is available
  • 18 mentions across 7 observed days
  • Momentum state: declining

What's happening

  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 14 signals
  • Disclosure: 10 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 6 mentions (2026-03-22); latest day: 1
  • 18 total mentions across 7 days

Affected systems

Vendors
Products
qvr_pro

Deep dive

Activity timeline18 mentions / 7d
02356Mentions · 2026-03-20: 1Mentions · 2026-03-21: 3Mentions · 2026-03-22: 6Mentions · 2026-03-23: 5Mentions · 2026-03-26: 1Mentions · 2026-03-30: 1Mentions · 2026-04-15: 1Patch / Workaround · 2026-03-21: 2Patch / Workaround · 2026-03-22: 3Patch / Workaround · 2026-03-23: 3Technical Details · 2026-03-20: 1Technical Details · 2026-03-21: 3Technical Details · 2026-03-22: 6Technical Details · 2026-03-23: 2Technical Details · 2026-03-30: 1Technical Details · 2026-04-15: 103-2003-2103-2203-2303-2603-3004-15
Signal classification3 categories
Disclosure
1055.6%
Patch
633.3%
General
211.1%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-03-201
Disclosure1
2026-03-213
Disclosure1Patch2
2026-03-226
Disclosure4Patch2
2026-03-235
Disclosure1General2Patch2
2026-03-261
Disclosure1
2026-03-301
Disclosure1
2026-04-151
Disclosure1
Full discourse18 posts
  • Gray Hats@the_yellow_fall
    Patch

    QNAP warns of a critical 9.3 CVSS flaw (CVE-2026-22898) allowing remote attackers to bypass authentication and access QVR Pro surveillance systems. Patch now. #QNAP #QVRPro #CVE #CyberSecurity #InfoSec #SurveillanceSecurity #Vulnerability #PatchAlert https://securityonline.info/critical-9-3-cvss-flaw-qnap-qvr-pro-surveillance-systems-cve-2026-22898/ https://t.co/wXLqS5chGF

    Post summary

    QNAP reports a critical CVSS‑9.3 flaw (CVE‑2026‑22898) that lets remote attackers bypass authentication to access QVR Pro systems, and urges users to apply the available patch.

    190185777
    10.7K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    IPカメラ管理製品QNAP QVR Proに重大(Critical)な脆弱性。CVE-2026-22898はCVSSスコア9.3で、重要機能における認証の欠如。悪用された場合システムに外部からアクセスされる可能性。修正版提供あり。 https://securityonline.info/critical-9-3-cvss-flaw-qnap-qvr-pro-surveillance-systems-cve-2026-22898/

    Post summary

    The post reports CVE-2026-22898, an authentication bypass vulnerability in QNAP QVR Pro with a CVSS score of 9.3, and confirms that a patch has been released.

    000611.0K
    7.3K followersView on X
  • Dr.Mashari@GMashari
    Patch

    📌 ثغرة حرجة (CVSS 9.3) في QNAP QVR Pro تهدد أنظمة المراقبة 🛡️ الفئة: ثغرة 📝 الملخص: أصدرت شركة QNAP Systems تحذيراً أمنياً حرجاً بشأن ثغرة خطيرة (CVE-2026-22898) في حل المراقبة QVR Pro. تحمل الثغرة تصنيف CVSS يبلغ 9.3، مما يشير إلى قدرتها على السماح للمهاجمين بتنفيذ تعليمات برمجية عن بعد (remote code execution). يمكن لهذه الثغرة أن تعرض أنظمة المراقبة للخطر الشديد، مما يتيح التحكم الكامل للمهاجمين في الأجهزة المتأثرة. يُنصح بشدة بتطبيق التحديثات الأمنية الصادرة عن QNAP فوراً للتخفيف من هذا التهديد الحرج وحماية البنى التحتية للمراقبة. 🗓️ تاريخ النشر: 21/03/2026 🔗 للمزيد: https://securityonline.info/critical-9-3-cvss-flaw-qnap-qvr-pro-surveillance-systems-cve-2026-22898/

    Post summary

    QNAP issues a critical advisory for CVE-2026-22898 in QVR Pro, highlighting a remote code execution flaw (CVSS 9.3) and urging users to apply available security patches immediately.

    01021111
    9.0K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-20131 2 - CVE-2026-22898 3 - CVE-2014-4113 4 - CVE-2026-4528 5 - CVE-2022-43555 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    A simple list of the top five trending CVEs with no further context or technical detail provided.

    01020129
    1.7K followersView on X
  • Misbar | مسبار@MisbarSec
    Patch

    📌 ثغرة حرجة (CVSS 9.3) في QNAP QVR Pro تهدد أنظمة المراقبة أصدرت شركة QNAP Systems تحذيراً أمنياً حرجاً بشأن ثغرة خطيرة (CVE-2026-22898) في حل المراقبة QVR Pro. تحمل الثغرة تصنيف CVSS يبلغ 9.3، مما يشير إلى قدرتها على السماح للمهاجمين بتنفيذ تعليمات برمجية عن بعد (remote code execution). يمكن لهذه الثغرة أن تعرض أنظمة المراقبة للخطر الشديد، مما يتيح التحكم الكامل للمهاجمين في الأجهزة المتأثرة. يُنصح بشدة بتطبيق التحديثات الأمنية الصادرة عن QNAP فوراً للتخفيف من هذا التهديد الحرج وحماية البنى التحتية للمراقبة. 🔗 للمزيد: https://securityonline.info/critical-9-3-cvss-flaw-qnap-qvr-pro-surveillance-systems-cve-2026-22898/ #الامن_السيبراني #CyberSecurity #cve

    Post summary

    QNAP announced CVE‑2026‑22898 with a CVSS 9.3 remote code execution severity, urging users to immediately apply vendor security patches and updates.

    0003081
    73 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    QNAP QVR Pro の脆弱性 CVE-2026-22898 が FIX:アクセス制御の不備とシステム侵害の可能性 https://iototsecnews.jp/2026/03/23/critical-qnap-qvr-pro-vulnerability-let-remote-attackers-gain-access-to-the-system/ この脆弱性 CVE-2026-22898 の原因は、認証チェックの欠如にあります。本来であれば、システムへのアクセスにおいては、正しい手続きを確認する仕組みが必要ですが、特定の機能において、そのプロセスに不備が発見されました。その結果、認証情報を持たない外部の攻撃者であっても、大切な監視データやネットワーク内部へ侵入できてしまう状態になっていました。ご利用のチームは、ご注意ください。 #CVE202622898 #QNAP #QVRPro #Vulnerability

    Post summary

    CVE-2026-22898 is an authentication bypass flaw in QNAP QVR Pro allowing remote attackers to gain system access and view monitoring data.

    01000118
    481 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    General

    QNAPのQVR Proに致命的な脆弱性(CVE-2026-22898) https://rocket-boys.co.jp/security-measures-lab/qnap-qvr-pro-critical-vulnerability-cve-2026-22898/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The post mentions a critical vulnerability (CVE-2026-22898) in QNAP QVR Pro and includes a link, but provides no technical details, PoC, exploit code, or patch information.

    0001098
    340 followersView on X
  • Israel@f1tym1
    Disclosure

    Critical QNAP QVR Pro Vulnerability Let Remote Attackers Gain Access to the System https://ift.tt/gJC0LYm QNAP has released a critical security advisory addressing a severe vulnerability in its QVR Pro surveillance software. Tracked as CVE-2026-22898, this flaw allows remote…

    Post summary

    QNAP announced a critical advisory for CVE‑2026‑22898 in its QVR Pro software, highlighting a remote access flaw that could let attackers gain system access; no proof‑of‑concept or exploit code was referenced.

    0000145
    953 followersView on X
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-292|CVE-2026-22898] QNAP TS-453E QVRPro excpostgres Exposed Dangerous Method Remote Code Execution Vulnerability (CVSS 8.8; Credit: Daniel FREDERIC from Fuzzinglabs, Julien COHEN-SCALI from Fuzzinglabs, Patrick VENTUZELO from Fuzzinglabs) https://www.zerodayinitiative.com/advisories/ZDI-26-292/

    Post summary

    The advisory announces a remote code execution vulnerability (CVE-2026-22898) in QNAP QVRPro with a CVSS score of 8.8, but provides no PoC, exploit code, patch details, or evidence of active exploitation.

    00000494
    5.4K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos QNAP ❗ CVE-2026-22898 ❗ CVE-2026-22897 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-qnap-3/ https://t.co/WxYSAXtK98

    Post summary

    The tweet alerts that two QNAP CVEs exist and points to an external page for additional information.

    00000111
    6.6K followersView on X
  • ThreatCluster@threatcluster
    Patch

    QNAP warns of critical QVR Pro bug CVE-2026-22898 allowing unauth remote access on 2.7.x. Patch to 2.7.4.1485 immediately, no exploitation reported yet. #Vulnerability https://threatcluster.io/cluster/critical-qnap-qvr-pro-vulnerability-exposes-systems-to-remot-d386f27e

    Post summary

    QNAP warns that CVE-2026-22898 in QVR Pro 2.7.x enables unauthenticated remote access, urging users to patch to version 2.7.4.1485 immediately; no active exploitation has been reported.

    0000037
    112 followersView on X
  • StrongKeep Cybersecurity@StrongKeepCyber
    Patch

    Surveillance systems are in the crosshairs today: a 9.3/10 flaw in QNAP QVR Pro could let bad actors peek at feeds. If you run CCTV at your small business, patch now, limit access, and test from a safe account. Read more: https://securityonline.info/critical-9-3-cvss-flaw-qnap-qvr-pro-surveillance-systems-cve-2026-22898/

    Post summary

    The post highlights a high‑severity (CVSS 9.3) vulnerability in QNAP QVR Pro that permits attackers to view camera feeds, urging users to apply patches and tighten access controls.

    0000038
    2 followersView on X
  • VulnTracker@vuln_tracker
    Disclosure

    @the_yellow_fall CVSS 9.3 auth bypass on surveillance systems is nightmare fuel. CVE-2026-22898 means anyone can remotely access QNAP QVR Pro camera feeds without credentials. If you're running NAS-based surveillance, patch this immediately. Track QNAP vulnerabilities: https://vulntracker.io

    Post summary

    A high‑severity CVE (9.3) allows unauthenticated remote access to QNAP QVR Pro camera feeds; users are urged to patch immediately.

    0000038
    445 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-22898 A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers can then exploit the vulnerability to gain acce… https://www.cve.org/CVERecord?id=CVE-2026-22898 ----- Traducción: CVE-2026-22898 Una… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑22898, a missing authentication flaw in QVR Pro that could allow remote attackers to exploit a critical function.

    0000017
    61 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22898 A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers can then exploit the vulnerability to gain acce… https://www.cve.org/CVERecord?id=CVE-2026-22898

    Post summary

    The tweet reports a newly disclosed missing-authentication vulnerability (CVE-2026-22898) in QVR Pro that allows remote attackers to gain unauthorized access.

    00000111
    56.8K followersView on X
  • Karma-X@Karma_X_Inc
    Disclosure

    Critical 9.3 CVSS Flaw in QNAP QVR Pro Exposes Surveillance Systems https://securityonline.info/critical-9-3-cvss-flaw-qnap-qvr-pro-surveillance-systems-cve-2026-22898/

    Post summary

    The text announces a critical 9.3‑rated vulnerability (CVE‑2026‑22898) affecting QNAP QVR Pro surveillance systems, but it does not include PoC, exploit code, or mitigation details.

    0000045
    70 followersView on X
  • CrowdCyber 🌐@CrowdCyber_Com
    Disclosure

    Critical 9.3 CVSS Flaw in QNAP QVR Pro Exposes Surveillance Systems https://securityonline.info/critical-9-3-cvss-flaw-qnap-qvr-pro-surveillance-systems-cve-2026-22898/

    Post summary

    The article announces a critical 9.3 CVSS flaw (CVE‑2026‑22898) in QNAP QVR Pro that could expose surveillance systems.

    0000037
    253 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-22898: QVR Pr... QNAP's QVR Pro drops auth checks on critical functions - network-accessible 9.3 CVSS goldmine for instant system compromise. #QVRPwned #QNAPFail. https://zerodaysignal.com/vulnerability/CVE-2026-22898 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet discloses a high‑scoring CVE-2026-22898 affecting QNAP QVR Pro, highlighting dropped authentication checks that enable instant system compromise, but provides no PoC or exploit code.

    0000065
    155 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appqnapqvr_pro---

Explore more