QNAP fixed four vulnerabilities demonstrated at Pwn2Own Ireland 2025
2026-03-24T02:51:44Z•57f78e4ac56c7325199675036658a59ab16328270366bd32a3973bdc56d5f8ad
aqua-securitycisadocker-hubfbiidentity-managerinfostealeriran-linkedknown-exploited-vulnerabilitieslaw-enforcementnasir-securityoperation-aliceoraclephishingpwn2ownqnaprussia-linkedsd-wansecurity-newssignalsupply-chainteampcptelegram-c2trivyvulnerabilitieswhatsapp
What happened
Multiple security events: QNAP patched four SD‑WAN router vulnerabilities (CVE-2025-62843 through CVE-2025-62846) that were chained at Pwn2Own Ireland 2025 to achieve root and arbitrary code execution; Oracle released a patch for a critical unauthenticated RCE (CVE-2026-21992, CVSS 9.8) in Identity Manager/Web Services Manager; a Trivy/Docker Hub supply‑chain compromise pushed malicious Trivy images (v0.69.4–0.69.6) containing TeamPCP infostealer code and led to defacement of ~44 Aqua Security repositories; Resecurity and FBI reporting highlights Iran-linked activity (Nasir Security targeting,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 57f78e4ac56c7325199675036658a59ab16328270366bd32a3973bdc56d5f8ad
- Enrichment time
- 2026-03-24T02:51:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.