Synology-SA-26:01 Storage Manager

Publish Time: UTC+8

Last Updated: UTC+8

Severity
Moderate
Status
Resolved

Abstract

Synology has released a security update for the Storage Manager package in DSM to address a vulnerability :
      • CVE-2026-2237 allows local attackers to obtain sensitive information.

Please refer to the 'Affected Products' table for the corresponding updates.

Affected Products

Product Severity Fixed Release Availability
Storage Manager for DSM 7.3 Moderate Upgrade to 1.0.1-1100 or above.
Storage Manager for DSM 7.2.2 Moderate Upgrade to 1.0.1-1100 or above.
Storage Manager for DSM 7.2.1 Moderate Upgrade to 1.0.1-1100 or above.

Mitigation

None

Detail

Acknowledgement

Simon Baaske (Serviceware)

Reference

CVE-2026-24061

Revision

Revision Date Description
1 2026-02-09 Initial public release.