Synology has patched eight security vulnerabilities in its NAS operating system DiskStation Manager (DSM). Two of them are rated critical with a CVSS score of 9.8 and allow unauthenticated remote attackers to read or write arbitrary files and trigger denial-of-service conditions. Operators of Synology NAS devices should apply the available updates without delay.
The Critical Vulnerabilities in Detail
CVE-2026-13684 (CVSS 9.8) affects the SCGI component of DSM. Insufficient output encoding in the Simple Common Gateway Interface lets an unauthenticated remote attacker read or write arbitrary files and cause a denial-of-service condition. Affected versions are DSM prior to 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, and 7.4-90075.
CVE-2026-13639 (CVSS 9.8) lies in the login logic: insufficient entropy makes security-relevant values predictable. This flaw is also exploitable without authentication, allowing the same arbitrary file access and denial-of-service attacks. The same DSM versions are affected.
Six Additional Vulnerabilities
The remaining six flaws include:
- CVE-2026-13673 (CVSS 8.8): Authenticated file operations
- CVE-2026-6205 (CVSS 8.1): Information disclosure
- CVE-2026-13635 (CVSS 5.3): Limited write access
- CVE-2026-13623 (CVSS 4.8), CVE-2026-13666 (CVSS 3.5), CVE-2026-13683 (CVSS 2.7): Further access and permission issues
Apply Updates Now
Synology has fixed all eight vulnerabilities in the following versions:
- DSM 7.3.2: version 7.3.2-86009-4 or later
- DSM 7.2.2: version 7.2.2-72806-9 or later
- DSM 7.2.1: version 7.2.1-69057-12 or later
- DSM 7.4: version 7.4-90075 or later
Synology provides no mitigation as an alternative to updating. Administrators should check which DSM branch is installed and update immediately.