Coordinated Vulnerability Disclosure Policy
Version: 1.0
Effective Date: August 28, 2026
Last Revised: August 28, 2026
QNAP reviews this Policy at least once a year to ensure that it remains up to date.
Issued by: QNAP Systems, Inc. Product Security Incident Response Team (PSIRT)
QNAP is dedicated to providing secure and trustworthy products and services, and values the security vulnerability information provided by security researchers, customers, partners, and other external parties. In order to promote responsible and efficient handling and disclosure of security vulnerabilities, QNAP has established a Coordinated Vulnerability Disclosure (CVD) process. If you discover a potential security vulnerability in any of QNAP products or services, we encourage you to submit a report in accordance with this Policy and to work with us to protect the vulnerability information concerned until appropriate remediation and risk mitigation measures have been completed.
1. Scope
This Policy applies to security vulnerabilities that may exist in the products, software, firmware, applications and related services that QNAP provides, as well as on websites and within infrastructure that QNAP makes available to the public. Security maintenance is provided in accordance with the support policy and support period applicable to each product. Where a vulnerability involves third-party or open-source components, QNAP will assess its actual impact on QNAP products on a case-by-case basis and coordinate with the relevant parties as necessary.
QNAP will accept and review every report submitted through the reporting channels listed in Section 2. Where a report is assessed as having no substantive security impact, QNAP will, in accordance with its internal processes, respond with the result of that assessment or refer the report to its technical support channels.
Qualification as a valid vulnerability report
QNAP assesses whether a report qualifies as a valid vulnerability report under this Policy based on the following criteria:
- The reported vulnerability affects any of QNAP products or services;
- the vulnerability report relates to publicly unknown information;
- the vulnerability report is not a result of automated tools or scans without supporting documentation.
QNAP's acceptance and handling of security vulnerability reports are not conditional upon the reporter possessing any particular qualification, nor will QNAP require a reporter to enter into a non-disclosure agreement (NDA) as a condition of accepting or handling a vulnerability report or awarding a reward. Whether a report qualifies for a reward will be determined separately in accordance with the terms of QNAP's Security Bounty Program. Such eligibility will not affect QNAP's obligations to accept and handle reports under this Policy.
2. How to Report a Security Vulnerability
(1) General Reports
For general vulnerability reports, please refer to the QNAP Security Advisories page. As a general rule, the following fall outside the scope of this Policy:
- Vulnerabilities that have already been publicly disclosed, or are already listed in a QNAP Security Advisory, CVE, or other publicly available security advisory listing
- Known vulnerabilities for which QNAP has already released a patch or mitigation
- Vulnerabilities in products provided by other vendors, or requests for further information regarding such vulnerabilities
- Vulnerabilities identified on websites other than qnap.com, or in services not operated by QNAP
- Malware identified on mobile devices
- Reports consisting solely of the results of automated tools or scans without supporting documentation
- Non-security matters such as technical support, product configuration, system updates, hardware repair, or assistance with installing patches
Technical support or issues arising from the use of QNAP products should be submitted through QNAP Customer Service. The other matters listed above do not require reporting under this Policy.
(2) Special Reports
QNAP provides the following dedicated reporting channels for special types of security reports. Please select the appropriate channel based on the situation:
| Situation | Reporting Channel |
|---|---|
| Actively Exploited Vulnerability (AEV) Confirmed Severe Incident |
CRA Security Reporting (QNAP's cybersecurity incident reporting platform, hereinafter the "CRA Reporting Platform") Note: Although this platform was established in response to the EU Cyber Resilience Act (CRA) and other cybersecurity regulations, it is available to all QNAP product users and researchers worldwide. If you discover a vulnerability being actively exploited or a severe security incident that meets the applicable criteria, please report it immediately through this channel. |
| Bounty Program | Security Bounty Program When submitting a report, please provide the product name, QTS/QES version, affected app version, a description of the vulnerability, and steps to reproduce; contact information and the PGP Public Key are available on that page. |
If the information available to you indicates that a vulnerability has been actively exploited, or if you discover an incident that may have a significant security impact on QNAP products or their users, please report it promptly through the CRA Reporting Platform.
You only need to describe the facts and evidence you have observed. QNAP will determine whether the report meets the statutory reporting criteria under the EU Cyber Resilience Act (CRA); reporters are not required to make this determination themselves. However, to ensure that your report is routed to the appropriate handling process, please refer to the order of the channels in the table above and select the appropriate channel accordingly. The CRA Reporting Platform should be used only when a vulnerability has been actively exploited or a severe security incident has occurred.
To assist QNAP in analyzing and handling the report, please provide the following information where possible:
- Affected products, models, and software/firmware versions
- Description of the vulnerability
- Time of the incident
- Observed impact
- Method of attack or exploitation
- Indicators of Compromise (IoC)
- Supporting evidence such as logs, packet captures, and screenshots
- Known vulnerability identifiers, such as CVE or EUVD identifiers
- Contact information through which QNAP can reach you
If your report contains sensitive information, QNAP recommends encrypting it with the PGP Public Key provided by QNAP before transmission. QNAP supports the security.txt standard defined in RFC 9116. The file is available at https://www.qnap.com/.well-known/security.txt and provides QNAP's official security contact information, reporting channels, a link to this Policy, and encryption information. Please refer to the latest version available online.
3. How QNAP Handles Reports
QNAP will, based on the content of the report and the reporting channel used, take appropriate vulnerability handling or cybersecurity incident response measures in accordance with applicable laws and regulations.
(1) Handling of General Product Security Vulnerability Reports
Upon receiving a report, QNAP will review the reported information and create a tracking record. Where necessary, QNAP may contact the reporter to obtain additional information, conduct vulnerability verification and risk assessment, and coordinate with the relevant product and development teams to conduct investigation and root cause analysis, as well as implement necessary security updates, patches, or other risk mitigation measures.
(2) Actively Exploited Vulnerabilities or Confirmed Severe Security Incidents
Reports involving actively exploited vulnerabilities or confirmed severe security incidents will be handled through QNAP's cybersecurity incident and CRA response processes. Based on the information obtained, QNAP will confirm the incident and assess its impact, and determine whether the applicable mandatory reporting criteria under the EU Cyber Resilience Act (CRA) are met. If QNAP determines that the mandatory reporting criteria are met, QNAP will, in accordance with applicable legal requirements, submit the required reports through the CRA Single Reporting Platform (SRP) to the designated Coordinating CSIRT and ENISA. QNAP will also take necessary measures based on the actual risk, including investigation, risk mitigation, security remediation, and user notification.
Pursuant to Article 14(7) of the CRA, QNAP has designated CERT-Bund (Germany) as its corresponding national CSIRT and will maintain the same point of contact throughout the handling of a single vulnerability. Following the initial report, QNAP will continue to provide the CSIRT with all newly available information, mitigation measures, and their implementation timelines, and will coordinate with it accordingly.
(3) Handling of Security Bounty Program Reports
Vulnerabilities falling within the scope and eligibility conditions of the Security Bounty Program may be eligible for a reward. The applicable products, vulnerability types, reward conditions, exclusions, and other rules are governed by the terms published by QNAP. Submission of a vulnerability report does not guarantee eligibility for a reward (QNAP Security Bounty Program).
(4) Vulnerability Identifiers and Security Advisories
QNAP will assess whether to assign or coordinate a CVE identifier based on the nature of the vulnerability, the extent of its impact, and applicable requirements. For vulnerabilities that have a security impact on users and require public disclosure, QNAP will publish relevant information through Security Advisories, product release notes, or other appropriate means. The content and timing of public disclosures will prioritize reducing security risks to users.
Where a vulnerability or incident is subject to mandatory reporting requirements, QNAP will make the required reports within the statutory time limits. Certain security issues may require additional time for investigation, cross-product impact analysis, root cause determination, patch development, and validation. The actual handling time will vary depending on the complexity and scope of the vulnerability or incident and its impact. QNAP will maintain appropriate communication with the reporter throughout the handling process.
4. Coordinated Disclosure Principles
To reduce the risk of malicious exploitation and to protect users, QNAP asks reporters to coordinate the timing of public disclosure of vulnerability information with QNAP until QNAP has completed its investigation and provided an appropriate patch or risk mitigation measure. During the coordinated handling period, please refrain from: publicly disclosing, without prior coordination, technical details of unpatched vulnerabilities or exploit code that could be used directly for attacks; providing vulnerability information to third parties who may use it to conduct malicious activity; and conducting testing that may cause service disruption, data loss, or impact on other users.
QNAP will coordinate a reasonable disclosure method and timeline with the reporter based on the risk of the vulnerability, remediation progress, the need to protect users, and other relevant factors. Where an actively exploited vulnerability or a severe security incident is involved, the content and timing of disclosure may additionally be subject to applicable regulatory requirements and the instructions of the competent authorities.
5. End of CVD Process
QNAP considers the vulnerability reporting process complete under any of the following circumstances:
- The reported issue is determined, following investigation, to be unfounded;
- the vulnerability in a service (such as a web service) has been remediated and publicly disclosed;
- the vulnerability has been mitigated or remediated through an appropriate security update or patch and publicly disclosed;
- the reporter has failed to respond to technical or content-related inquiries for more than 30 days, such that the report can only be handled to a limited extent or cannot be further processed;
- the vulnerability has been publicly disclosed and, following consultation with the corresponding national CSIRT, it can no longer reasonably be expected that the vulnerability will be mitigated or remediated.
6. Security Research Guidelines and Safe Harbor
QNAP supports good-faith and responsible security research. When conducting security research, please comply with applicable laws and avoid causing unnecessary impact on QNAP, QNAP customers, or other third parties.
When conducting security research, please do not:
- Destroy, modify, or delete data that you do not own
- Access, download, or distribute personal data or other confidential information without authorization
- Perform DoS/DDoS testing that may render systems or services unavailable
- Conduct social engineering or phishing against QNAP employees, customers, or partners
- Carry out physical attacks or unauthorized physical access
- Take actions beyond what is reasonably necessary to confirm the existence of a vulnerability
- Use a vulnerability for any unlawful or malicious purpose
If you accidentally access data or system resources that are outside the scope of your research, please cease any further access and notify QNAP as soon as possible.
For security research conducted in good faith in accordance with this Policy and the guidelines set out above, QNAP will not take legal action against the researcher and will not consider such research to constitute a violation of QNAP's Terms of Service or End User License Agreement. This protection applies only to research activities that fall within the scope of this Policy. If the research activities exceed the scope of this Policy, QNAP will evaluate the circumstances on a case-by-case basis. If you are unsure whether your planned research falls within the scope of this Policy, you may contact QNAP PSIRT in advance for confirmation. Even if a reporter does not fully comply with the guidelines set out above, QNAP will nevertheless make reasonable efforts to review and address the report. QNAP expects all participants to treat one another with respect. Discriminatory, sexist, or abusive conduct will not be tolerated.
7. Confidentiality and Use of Information
QNAP treats every vulnerability report as confidential to the extent permitted by applicable law, except for information necessary for the public disclosure of a vulnerability.
QNAP will process the information provided by reporters for the purposes of vulnerability handling and remediation, statutory notification, and product security improvement. Where necessary, relevant information may be provided to QNAP's internal units responsible for product security, product development, or legal affairs. Except as required by law or statutory reporting obligations under the Cyber Resilience Act (CRA), QNAP will not provide your personal data to third parties without your express consent.
Personal data provided by reporters will be processed and retained by QNAP only to the extent necessary and in accordance with the QNAP Privacy Policy. QNAP will apply appropriate protective measures based on the sensitivity of the information.