CVE-2026-13639
CVSS 9.8 CRITICAL: an insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12…
Vulnerabilities & Exploits
Synology and national CERTs disclosed eight vulnerabilities in DiskStation Manager (DSM), including two critical flaws that can let an unauthenticated remote attacker read or write arbitrary files. Synology published branch-specific fixes for DSM 7.2.1, 7.2.2, 7.3, and 7.4.
The two critical bugs sit in login handling and SCGI output encoding. In plain terms, a malformed request can be treated like a filesystem action or cause data to be returned without proper protection, so the impact is not just a crash: the NAS’s shared files can be exposed, altered, or made unavailable.
For operators with mixed DSM versions, the important detail is that one patch line does not cover the fleet. If a Synology box sits behind shared storage or backup workflows, the vulnerable surface is the filesystem on the appliance itself, and tampering there can affect every service that depends on it.
2 sources · 14h ago
CVSS 9.8 CRITICAL: an insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12…
CVSS 9.8 CRITICAL: an improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before…
CSIRT Italia / ACN
Risolte vulnerabilità in Synology DiskStation Manager (DSM)
Rilevate diverse vulnerabilità di sicurezza, di cui due con gravità “alta” e due con gravità “critica” in Synology DiskStation Manager (DSM).
originalINCIBE-CERT
Múltiples vulnerabilidades en DSM de Synology
Lam Jun Rong, DungNBN, Scamman, Uky, Juhyeop Lee, Brendan O'Rourke y WinD39 han informado sobre 8 vuln
originalPart of the PlainSec briefing for 2026-09-21
Every edition of this story: Synology DSM Fix Spans Four Release Branches