Back Heise.De Update now: Attackers could read arbitrary data from Synology NAS
NAS manufacturer Synology has published security advisories for its in-house operating system, the “DiskStation Manager” (DSM). These fix eight security vulnerabilities, two of them critical. Both flaws could allow attackers to read data from a Synology NAS (Network Attached Storage) if they have network access to the device.
The security vulnerabilities with CVE IDs CVE-2026-13684 and CVE-2026-13639 have received a CVSS score of 9.8 points – and should be fixed by administrators as quickly as possible. They allow attackers to remotely read or write arbitrary files and – for example, through deletion – to carry out denial-of-service attacks. The brief description of the vulnerabilities on the Synology advisory page is likely to quickly alert ransomware authors and other criminals, as their exploitation is very easy according to Synology.
Two other bugs also allow attackers to read or manipulate data – but only after successfully logging into the system. And a classic from the security vulnerability mothball has also been found by a security researcher in Synology DSM: A low-severity SQL injection (CVE-2026-13683). In total, Synology reports eight CVE IDs as fixed.
Admins should install updated versions of DSM that fix the errors as quickly as possible. These are, in detail:
DSM 7.2.2-72806-9 and
Synology does not provide a temporary solution – if you cannot patch, you should temporarily repurpose the NAS as NDS (Network Detached Storage). The manufacturer has recently clashed with customers because it tried to chain them to expensive proprietary storage media through a compatibility check.
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
