Skip to content
COOEY

FAIL › dossier

QTS

PRODUCT

· dossier confidence 85%

QTS Realty Trust is a public data center REIT providing secure, compliant infrastructure and managed services. Its security posture is compromised by critical, actively exploited vulnerabilities in its third-party software stack, requiring immediate attention to supply chain risk management and vendor patching processes.

PROFILE
CategoryData Center REITWhat they doQTS Realty Trust, Inc. is a leading provider of secure, compliant data center solutions, hybrid cloud, and fully managed services. It owns, operates, or manages 24 data centers supporting over 1,100 customers across North America, Europe, and Asia Pacific.Founded2003HQChicago, IL, United StatesSize24 data centers, 1,100+ customersOwnershippublic Websitehttps://www.qts.com ↗
SECURITY POSTURE

QTS operates a large-scale data center infrastructure with a focus on secure, compliant solutions, but its security posture is heavily dependent on third-party hardware and software vendors. The internal failure history reveals critical vulnerabilities in its managed software stack (QNAP QTS) that were actively exploited, indicating a reliance on external components without sufficient compensating controls or rapid patching.

Notable failures
  • CVE-2019-7193: QNAP QTS RCE exploited in ransomware attacks
  • CVE-2018-19949: Command injection vulnerability in managed software
  • CVE-2025-66276: QuTS hero unaffected (no failure)
Patterns: reliance on third-party software with critical unpatched vulnerabilities; active exploitation of managed software flaws in the wild
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2022-06-08 CVE-2019-7193 critical QNAP QTS suffered an improper input validation flaw allowing remote code execution, which was actively exploited in the wild and linked to ransomware attacks.
2026-06-10 CVE-2025-66276 critical CVE-2025-66276: QuTS hero is not affected. We have already fixed the vulnerability in the follo
2020-10-28 CVE-2018-19949 critical CVE-2018-19949: If exploited, this command injection vulnerability could allow remote attackers
Open questions: What is QTS Realty Trust, Inc.'s actual security posture regarding data center physical and logical security? · Are there any unreported security incidents or compliance failures not in the provided internal failure history?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-26 04:24:12.797658+00:00