Synology-SA-26:06 DSM

Publish Time: UTC+8

Last Updated: UTC+8

Severity
Important
Status
Resolved

Abstract

Synology has released a security update for the DSM to address multiple vulnerabilities :
      • CVE-2026-40530, CVE-2026-4036, CVE-2026-40531, CVE-2026-40532, CVE-2026-40534, CVE-2026-40536, CVE-2026-40537 allow remote authenticated users to read or write arbitrary or limited files, conduct denial-of-service attacks, and obtain sensitive or non-sensitive information, including arbitrary sharing files.

      • CVE-2026-40533, CVE-2026-40535, and CVE-2026-40538 allow remote attackers to obtain non-sensitive information, read or write limited files, and conduct limited denial-of-service attacks.

      • CVE-2026-40539 allows man-in-the-middle attackers to read or write arbitrary files and conduct denial-of-service attacks.

Please refer to the 'Affected Products' table for the corresponding updates.

Affected Products

Product Severity Fixed Release Availability
DSM 7.3 Important Upgrade to 7.3.2-86009-2 or above.
DSM 7.2.2 Important Upgrade to 7.2.2-72806-7 or above.
DSM 7.2.1 Important Upgrade to 7.2.1-69057-10 or above.

Mitigation

None

Detail

Acknowledgement

  • Warisse Valentin (Aytio) :
        CVE-2026-40530, CVE-2026-40535, CVE-2026-40537
  • Ben R of Interrupt Labs (https://www.interruptlabs.co.uk) :
        CVE-2026-40539
  • juhye0p, ZZoMb1E (STEALIEN INC.) :
        CVE-2026-4036
  • Pumpkin (@u1f383) from DEVCORE Research Team :
        CVE-2026-40531
  • izut and Searat from the Web Hacker Team(https://github.com/web-hacker-team/):
        CVE-2026-40532, CVE-2026-40536
  • Allendraa A/L Anbalagan :
        CVE-2026-40533
  • HE JIASHENG :
        CVE-2026-40534
  • Andreas Rothenbacher (error401.de) :
        CVE-2026-40538

Revision

Revision Date Description
1 2026-04-15 Initial public release.