QNAP fixed four vulnerabilities demonstrated at Pwn2Own Ireland 2025

2026-03-24T02:51:44Z57f78e4ac56c7325199675036658a59ab16328270366bd32a3973bdc56d5f8ad
aqua-securitycisadocker-hubfbiidentity-managerinfostealeriran-linkedknown-exploited-vulnerabilitieslaw-enforcementnasir-securityoperation-aliceoraclephishingpwn2ownqnaprussia-linkedsd-wansecurity-newssignalsupply-chainteampcptelegram-c2trivyvulnerabilitieswhatsapp

What happened

Multiple security events: QNAP patched four SD‑WAN router vulnerabilities (CVE-2025-62843 through CVE-2025-62846) that were chained at Pwn2Own Ireland 2025 to achieve root and arbitrary code execution; Oracle released a patch for a critical unauthenticated RCE (CVE-2026-21992, CVSS 9.8) in Identity Manager/Web Services Manager; a Trivy/Docker Hub supply‑chain compromise pushed malicious Trivy images (v0.69.4–0.69.6) containing TeamPCP infostealer code and led to defacement of ~44 Aqua Security repositories; Resecurity and FBI reporting highlights Iran-linked activity (Nasir Security targeting,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
57f78e4ac56c7325199675036658a59ab16328270366bd32a3973bdc56d5f8ad
Enrichment time
2026-03-24T02:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · QNAP fixed four vulnerabilities demonstrated at Pwn2Own Ireland 2025 · Baitaphish