VYPR
patchPublished Sep 18, 2026· Updated Sep 22, 2026· 1 source

Synology DSM: 19 Vulnerabilities Disclosed, Including Critical File Access Flaws

Key findings • 19 vulnerabilities disclosed in Synology DSM on September 18, 2026. • Critical and High severity flaws include arbitrary file read/write and DoS capabilities. • Vulnerabili…

Key findings

  • 19 vulnerabilities disclosed in Synology DSM on September 18, 2026.
  • Critical and High severity flaws include arbitrary file read/write and DoS capabilities.
  • Vulnerabilities affect multiple APIs including Upload, LDAP, SCGI, and Email.
  • Affected versions predate 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, and 7.4-90075.
  • Patches are available; users urged to update DSM promptly.

On September 18, 2026, Synology disclosed a significant batch of 19 vulnerabilities affecting its DiskStation Manager (DSM) software. These vulnerabilities span various components and impact authenticated users, with several carrying high or critical severity ratings. The disclosures highlight a range of security weaknesses, including issues with file handling, authentication, and input validation, potentially allowing attackers to read or write arbitrary files, conduct denial-of-service attacks, and obtain sensitive information.

Several vulnerabilities fall into the category of improper file handling. CVE-2026-6205, a High severity vulnerability, involves an external control of file name or path in the Upload API, allowing authenticated users to write arbitrary files. Similarly, CVE-2026-13684, a Critical severity flaw in SCGI, and CVE-2026-13673, a High severity vulnerability in the LDAP API, also permit arbitrary file read/write operations and denial-of-service attacks. CVE-2026-13639, another Critical severity vulnerability, stems from insufficient entropy in login logic, leading to similar file manipulation and DoS risks.

Other vulnerabilities target specific API functions. CVE-2026-4036, a Medium severity SQL injection flaw in the Sharing API, allows authenticated users to obtain arbitrary sharing files. CVE-2026-40539, a High severity vulnerability in the Email API, involves improper certificate validation and could enable man-in-the-middle attacks for reading or writing files. Cross-site scripting (XSS) vulnerabilities are also present, such as CVE-2026-40534 in the Video API and CVE-2026-13623 in the Theme API, which can allow authenticated users to read or write limited files under certain conditions.

The batch also includes vulnerabilities related to information exposure and access control. CVE-2026-40537, a Medium severity SSRF vulnerability in the PersonMail API, allows authenticated users to obtain non-sensitive information. CVE-2026-40533, another Medium severity vulnerability in the Desktop API, exposes sensitive information through data queries. CVE-2026-40532, a Medium severity direct request vulnerability in Wallpaper Path, enables authenticated users to obtain sensitive information. Additionally, CVE-2026-40538 and CVE-2026-13635, both with Low severity, relate to improper restriction of authentication attempts and output encoding, respectively.

Synology has addressed these vulnerabilities with patches released in various versions of DiskStation Manager. The affected versions are generally prior to 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, and 7.4-90075. Users are advised to update their DSM to the latest available versions to mitigate these risks. The wide range of vulnerabilities and their varying severity levels underscore the importance of regular security updates for Synology NAS devices.

This coordinated disclosure of 19 vulnerabilities on a single day highlights a significant security event for Synology DSM users. The presence of multiple critical and high-severity flaws, particularly those allowing arbitrary file read/write and denial-of-service, necessitates prompt attention from administrators. Users should prioritize updating their DSM installations to the patched versions to protect their data and system integrity. The variety of affected APIs and vulnerability types suggests a need for ongoing vigilance and adherence to security best practices when managing Synology devices.

Synthesized by Vypr AI