Multiple Vulnerabilities in Synology DiskStation Manager (DSM)
23 September 2026
Attackers can exploit multiple vulnerabilities in Synology DiskStation Manager (DSM) to read or write arbitrary files and conduct denial-of-service attacks. Patch immediately.
Background
Synology has released security updates to address multiple vulnerabilities (CVE-2026-13639, CVE-2026-13684, CVE-2026-13673 and CVE-2026-6205) affecting Synology DiskStation Manager (DSM). The vulnerabilities have Common Vulnerability Scoring System (CVSS) scores of: CVE-2026-13639 at 9.8, CVE-2026-13684 at 9.8, CVE-2026-13673 at 8.8 and CVE-2026-6205 at 8.1 out of 10.
Impact
Due to insufficient entropy in the login logic, improper encoding or escaping of output in SCGI, incorrect permission assignment for critical resource in the LDAP API and external control of file name or path in the Upload API, these vulnerabilities could allow remote attackers to read or write arbitrary files and conduct denial-of-service attacks against affected Synology DiskStation Manager (DSM) systems.
Affected Products
These vulnerabilities affect Synology DiskStation Manager (DSM) versions 7.4, 7.3, and 7.2.
Recommendations
Users and administrators of affected products are advised to update to the latest versions immediately.
References
https://www.synology.com/en-global/security/advisory/Synology_SA_26_13 (opens in new tab)
https://nvd.nist.gov/vuln/detail/CVE-2026-13639 (opens in new tab)
https://nvd.nist.gov/vuln/detail/CVE-2026-13684 (opens in new tab)
https://nvd.nist.gov/vuln/detail/CVE-2026-13673 (opens in new tab)
https://nvd.nist.gov/vuln/detail/CVE-2026-6205 (opens in new tab)
