Skip to content
Update now: Attackers could read arbitrary data from Synology NAS

Update now: Attackers could read arbitrary data from Synology NAS

Heise.De September 18, 2026

NAS manufacturer Synology has published security advisories for its in-house operating system, the “DiskStation Manager” (DSM). These fix eight security vulnerabilities, two of them critical. Both flaws could allow attackers to read data from a Synology NAS (Network Attached Storage) if they have network access to the device.

The security vulnerabilities with CVE IDs CVE-2026-13684 and CVE-2026-13639 have received a CVSS score of 9.8 points – and should be fixed by administrators as quickly as possible. They allow attackers to remotely read or write arbitrary files and – for example, through deletion – to carry out denial-of-service attacks. The brief description of the vulnerabilities on the Synology advisory page is likely to quickly alert ransomware authors and other criminals, as their exploitation is very easy according to Synology.

Two other bugs also allow attackers to read or manipulate data – but only after successfully logging into the system. And a classic from the security vulnerability mothball has also been found by a security researcher in Synology DSM: A low-severity SQL injection (CVE-2026-13683). In total, Synology reports eight CVE IDs as fixed.

Admins should install updated versions of DSM that fix the errors as quickly as possible. These are, in detail:

DSM 7.2.2-72806-9 and

Synology does not provide a temporary solution – if you cannot patch, you should temporarily repurpose the NAS as NDS (Network Detached Storage). The manufacturer has recently clashed with customers because it tried to chain them to expensive proprietary storage media through a compatibility check.

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.

Extracted Entities

Attack Types (2)

CWE Weaknesses (1)

Domains (1)

Platforms (1)