www.synology.com Critical Vulnerabilities in Synology DSM Expose NAS Devices to Remote Attacks
Article Content
- •Two critical vulnerabilities (CVE-2026-13684, CVE-2026-13639) allow remote file access.
- •Affected DSM versions include 7.4, 7.3, and 7.2; urgent patching is required.
- •Exploitation could lead to data breaches and denial-of-service attacks.
Synology has issued an advisory detailing eight security vulnerabilities in its DiskStation Manager (DSM) software, with CVE-2026-13684 and CVE-2026-13639 classified as critical, both scoring 9.8 on the CVSS scale. These flaws allow remote attackers to read or write arbitrary files and conduct denial-of-service attacks. Other vulnerabilities require authenticated access to exploit, including CVE-2026-13673, which also poses significant risks. Administrators are urged to upgrade to the latest DSM versions to mitigate these risks. The vulnerabilities were disclosed on September 18, 2026, and affect multiple DSM versions, including 7.4, 7.3, and 7.2. Synology has not provided temporary workarounds, emphasizing the urgency of applying patches. The advisory warns that these vulnerabilities could attract ransomware actors due to their ease of exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-13623 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…