Synology-SA-26:13 DSM

Publish Time: UTC+8

Last Updated: UTC+8

Severity
Critical
Status
Resolved

Abstract

Synology has released a security update for the DSM to address multiple vulnerabilities :
      • CVE-2026-13684, CVE-2026-13639, and CVE-2026-13635 allow remote attackers to read or write arbitrary files, conduct denial-of-service attacks, or obtain non-sensitive information.

      • CVE-2026-13673, CVE-2026-6205, and CVE-2026-13666 allow remote authenticated users to read or write arbitrary files, write limited files when a victim clicks a sharing URL, and conduct denial-of-service attacks.

      • CVE-2026-13623 and CVE-2026-13683 allow remote authenticated users with administrator privileges to read or write limited files or obtain non-sensitive information.

Please refer to the 'Affected Products' table for the corresponding updates.

Affected Products

Product Severity Fixed Release Availability
DSM 7.4 Critical Upgrade to 7.4-90075 or above.
DSM 7.3 Critical Upgrade to 7.3.2-86009-4 or above.
DSM 7.2.2 Critical Upgrade to 7.2.2-72806-9 or above.
DSM 7.2.1 Critical Upgrade to 7.2.1-69057-12 or above.

Mitigation

None

Detail

Acknowledgement

  • Lam Jun Rong (https://jro.sg)

  • DungNBN (@greengrass19000) from Viettel Cyber Security Research Lab (@vcslab) working with Scamman from Trung Tâm Săn Lỗi Lậu Hải Ngoại

  • Uky

  • Juhyeop Lee (STEALIEN INC.) https://www.stealien.com

  • Brendan O'Rourke

  • WinD39 from Viettel Cyber Security (https://www.linkedin.com/in/dinh-vu-17922227a/)

Revision

Revision Date Description
1 2026-09-18