Vulnerabilities & Exploits

Synology DSM Fix Spans Four Release Branches

Synology and national CERTs disclosed eight vulnerabilities in DiskStation Manager (DSM), including two critical flaws that can let an unauthenticated remote attacker read or write arbitrary files. Synology published branch-specific fixes for DSM 7.2.1, 7.2.2, 7.3, and 7.4.

The two critical bugs sit in login handling and SCGI output encoding. In plain terms, a malformed request can be treated like a filesystem action or cause data to be returned without proper protection, so the impact is not just a crash: the NAS’s shared files can be exposed, altered, or made unavailable.

For operators with mixed DSM versions, the important detail is that one patch line does not cover the fleet. If a Synology box sits behind shared storage or backup workflows, the vulnerable surface is the filesystem on the appliance itself, and tampering there can affect every service that depends on it.

2 sources · 14h ago

CVE-2026-13639

NVD KEV

CVSS 9.8 CRITICAL: an insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12…

CVE-2026-13684

NVD KEV

CVSS 9.8 CRITICAL: an improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before…

Timeline

Sources

Part of the PlainSec briefing for 2026-09-21

Every edition of this story: Synology DSM Fix Spans Four Release Branches

More from today