Skip to content
Critical Vulnerabilities in Synology DSM Expose NAS Devices to Remote Attacks

Critical Vulnerabilities in Synology DSM Expose NAS Devices to Remote Attacks

First seen 18 Sep 2026, 16:55 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 18, 2026 at 17:54 UTC
  • Two critical vulnerabilities (CVE-2026-13684, CVE-2026-13639) allow remote file access.
  • Affected DSM versions include 7.4, 7.3, and 7.2; urgent patching is required.
  • Exploitation could lead to data breaches and denial-of-service attacks.

Synology has issued an advisory detailing eight security vulnerabilities in its DiskStation Manager (DSM) software, with CVE-2026-13684 and CVE-2026-13639 classified as critical, both scoring 9.8 on the CVSS scale. These flaws allow remote attackers to read or write arbitrary files and conduct denial-of-service attacks. Other vulnerabilities require authenticated access to exploit, including CVE-2026-13673, which also poses significant risks. Administrators are urged to upgrade to the latest DSM versions to mitigate these risks. The vulnerabilities were disclosed on September 18, 2026, and affect multiple DSM versions, including 7.4, 7.3, and 7.2. Synology has not provided temporary workarounds, emphasizing the urgency of applying patches. The advisory warns that these vulnerabilities could attract ransomware actors due to their ease of exploitation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-18
Synology publishes security advisory
Synology discloses eight vulnerabilities in DSM, urging immediate updates to mitigate risks.
Synology
2026-09-18
Critical CVEs published
CVE-2026-13684 and CVE-2026-13639 are published, both rated critical with CVSS scores of 9.8.
Heise.De
2026-09-18
Patch availability announced
Synology announces patches for affected DSM versions, urging administrators to upgrade immediately.
Synology
2026-09-18
CVE-2026-13623 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-18
CVE-2026-13673 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-18
CVE-2026-6205 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-18
CVE-2026-13666 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-18
CVE-2026-13683 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-18
CVE-2026-13639 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-18
CVE-2026-13684 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (2)

Following this threat?

Track CVE-2026-13623 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed