Skip to content
Dark Web Intelligence on X: " SYNOLOGY DSM CRITICAL

Dark Web Intelligence on X: " SYNOLOGY DSM CRITICAL

X • September 19, 2026

Dark Web Intelligence on X: "🚨 SYNOLOGY DSM CRITICAL: UNAUTH ARBITRARY FILE R/W (CVSS 9.8)

Synology published Synology-SA-26:13 for DiskStation Manager, rating the advisory Critical.

Two unauthenticated remote vulnerabilities are scored CVSS 9.8:

• CVE-2026-13684 — SCGI improper encoding/escaping; arbitrary file read/write and DoS

• CVE-2026-13639 — login insufficient entropy; arbitrary file read/write and DoS

Additional Important issues allow authenticated arbitrary file read/write (CVE-2026-13673) and arbitrary write (CVE-2026-6205).

Affected: DSM 7.4 / 7.3 / 7.2.2 / 7.2.1. Fixed builds listed in the advisory. No workaround — upgrade.

Official advisory:

#DDW #DarkWeb #Synology #DSM #CVE #CyberSecurity #ThreatIntelligence"

🚨 SYNOLOGY DSM CRITICAL: UNAUTH ARBITRARY FILE R/W (CVSS 9.8)

Synology published Synology-SA-26:13 for DiskStation Manager, rating the advisory Critical.

Two unauthenticated remote vulnerabilities are scored CVSS 9.8:

• CVE-2026-13684 — SCGI improper encoding/escaping; arbitrary file read/write and DoS

• CVE-2026-13639 — login insufficient entropy; arbitrary file read/write and DoS

Additional Important issues allow authenticated arbitrary file read/write (CVE-2026-13673) and arbitrary write (CVE-2026-6205).

Affected: DSM 7.4 / 7.3 / 7.2.2 / 7.2.1. Fixed builds listed in the advisory. No workaround — upgrade.

🚨 SYNOLOGY DSM CRITICAL: UNAUTH ARBITRARY FILE R/W (CVSS 9.8)

Synology published Synology-SA-26:13 for DiskStation Manager, rating the advisory Critical.

Two unauthenticated remote vulnerabilities are scored CVSS 9.8:

• CVE-2026-13684 — SCGI improper encoding/escaping; arbitrary file read/write and DoS

• CVE-2026-13639 — login insufficient entropy; arbitrary file read/write and DoS

Additional Important issues allow authenticated arbitrary file read/write (CVE-2026-13673) and arbitrary write (CVE-2026-6205).

Affected: DSM 7.4 / 7.3 / 7.2.2 / 7.2.1. Fixed builds listed in the advisory. No workaround — upgrade.

Extracted Entities