Critical Security Vulnerability in Synology's BeeStation Addressed
Article Content
Browse articles
A critical security vulnerability (CVE-2025-12686, CVSS 9.8) was discovered in Synology's BeeStation during Pwn2Own 2025 in Ireland. This vulnerability allows attackers to execute arbitrary code remotely due to a buffer copy issue without proper size checking. Synology has released updates to mitigate this risk.
Ask AI about this cluster
Answers cite the sources they use
Updated 182d ago How this analysis works
More articles in this cluster (1)
Following this threat?
Track Qnap and CVE-2025-12686 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Vulnerabilities in openSUSE apr-util Require Immediate Patching Multiple critical vulnerabilities have been identified in the Apache Portable Runtime Utility (apr-util) affecting openSUSE systems. Key issues include CVE-2026-34191, a SQL Injection vulnerability, and CVE-2026-34501 and CVE-2026-34502, both heap buffer overflows. These vulnerabilities can lead to unauthorized access…
Multiple openSUSE Vulnerabilities Addressed in September 2026 Security Updates On September 2, 2026, openSUSE released multiple security updates addressing vulnerabilities across various packages, including incus, httpcomponents-client, kernel-devel, snpguest, tuxguitar, wget, and snphost. The updates include fixes for moderate security issues, with CVE identifiers for some vulnerabilities. The…