CVE-2026-22898 – QNAP QVR Pro

CVSS 9.8 CRITICAL

“When surveillance breaks, visibility turns into exposure.”

This patch addresses CVE-2026-22898 in QNAP QVR Pro, a critical vulnerability that could allow unauthorized access or control over the surveillance management system. Successful exploitation could expose sensitive video data or disrupt monitoring operations. The CVSS score is 9.3, which is Critical severity.

There is no verified evidence of active exploitation or publicly available proof-of-concept code at this time. Despite this, the high severity and exposure of surveillance infrastructure make this a high-priority patch for affected environments.

Key Details

Affected Product
Qnap Qvr Pro
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-306
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.