Synology Synology's mission is to manage and protect the world’s data
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Synology product.
RSS Feeds for Synology security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Synology products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Synology Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 48 vulnerabilities in Synology with an average score of 6.1 out of ten. Last year, in 2025 Synology had 24 security vulnerabilities published. That is, 24 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.37
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 48 | 6.10 |
| 2025 | 24 | 6.47 |
| 2024 | 29 | 6.05 |
| 2023 | 11 | 7.67 |
| 2022 | 35 | 7.78 |
| 2021 | 35 | 7.87 |
| 2020 | 22 | 7.26 |
| 2019 | 37 | 6.48 |
| 2018 | 30 | 6.72 |
It may take a day or so for new Synology vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Synology Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-40539 | Sep 18, 2026 |
CVE-2026-40539: Improper Cert Validation in Synology DSM Email API (pre-7.2.1)An improper certificate validation vulnerability in Email API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows man-in-the-middle attackers to read or write arbitrary files and conduct denial-of-service attacks. |
|
| CVE-2026-40538 | Sep 18, 2026 |
Synology DSM <7.2.2: Brute-Force Auth Allows Limited File ReadAn improper restriction of excessive authentication attempts vulnerability in Auto block in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to read limited files via brute-force attacks. |
|
| CVE-2026-40535 | Sep 18, 2026 |
DSM Desktop API Path Traversal (7.2.1) Remote File WriteAn improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to write limited files and conduct limited denial-of-service attacks. |
|
| CVE-2026-40533 | Sep 18, 2026 |
Synology DSM Desktop API Info Disclosure 7.3.2-86009-2 & earlierAn exposure of sensitive information through data queries vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to obtain non-sensitive information. |
|
| CVE-2026-40537 | Sep 18, 2026 |
Synology DSM SSRF in PersonMail API before 7.3.2-86009-2A server-side request forgery (SSRF) vulnerability in PersonMail API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information. |
|
| CVE-2026-40536 | Sep 18, 2026 |
Path Traversal in Synology DSM Audio API <7.2.1 Remote AuthAn improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information. |
|
| CVE-2026-40534 | Sep 18, 2026 |
Synology DSM XSS in Video API before 7.3.2-86009-2An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Video API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write limited files when the player is launched. |
|
| CVE-2026-40532 | Sep 18, 2026 |
Forced Browsing in Wallpaper Path (DSM 7.x<7.2.1) Enables Auth LeakA direct request ('forced browsing') vulnerability in Wallpaper Path in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain sensitive information. |
|
| CVE-2026-40531 | Sep 18, 2026 |
Integer Overflow in Synology DSM File Op before 7.3.2-86009-2 Enables DoSAn integer overflow or wraparound vulnerability in File Operation in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to conduct limited denial-of-service attacks. |
|
| CVE-2026-4036 | Sep 18, 2026 |
Synology DSM pre-7.3.2 SQLi via Sharing API remote authAn improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain arbitrary sharing files. |
|
| CVE-2026-40530 | Sep 18, 2026 |
CRLF Injection in Synology DSM <7.2.1-69057-10 allows file read/writeAn improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks after the system is rebooted. |
|
| CVE-2026-13683 | Sep 18, 2026 |
Synology DSM EventScheduler API SQLi <7.2.1/7.2.2/7.3.2/7.4An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in EventScheduler API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users with administrator privileges to obtain non-sensitive information. |
|
| CVE-2026-13623 | Sep 18, 2026 |
Synology DSM 7.2 Theme API XSS before 7.2.1-69057-12An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Theme API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users with administrator privileges to read or write limited files. |
|
| CVE-2026-13666 | Sep 18, 2026 |
CRLF Injection in Synology DSM 7.x Sharing API (v<7.2.1,7.2.2,7.3.2,7.4)An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write limited files when a victim clicks a sharing URL. |
|
| CVE-2026-6205 | Sep 18, 2026 |
Synology DSM External Control of File Path Vulnerability before 7.2.1-69057-12An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write arbitrary files and conduct denial-of-service attacks. |
|
| CVE-2026-13673 | Sep 18, 2026 |
Incorrect Perm Assign in Synology DSM LDAP API <7.2.1, 7.2.2, 7.3.2, 7.4An incorrect permission assignment for critical resource vulnerability in LDAP API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks. |
|
| CVE-2026-13635 | Sep 18, 2026 |
Synology DSM <7.4.1 Auth API XSS Escaping IssueAn improper encoding or escaping of output vulnerability in Auth API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to obtain non-sensitive information. |
|
| CVE-2026-13639 | Sep 18, 2026 |
Low Entropy in DSM Login (<7.2.1-69057-12) Enables Remote File Access & DoSAn insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks. |
|
| CVE-2026-13684 | Sep 18, 2026 |
SCGI Improper Escaping in Synology DSM <7.4 (pre7.4.0)An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks. |
|
| CVE-2026-9548 | Aug 28, 2026 |
Synology Chat Server XSS via extract domain <2.4.5-22148 allows file read/writeAn improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write restricted files and conduct limited denial-of-service attacks in DSM. |
|
| CVE-2026-9491 | Aug 28, 2026 |
Synology Chat Server SSRF in webhook before 2.4.5-22148 (remote auth)A server-ide request forgery (SSRF) vulnerability in webhook in Synology Chat Server before 2.4.5-22148 allows remote authenticated users to obtain non-sensitive information. |
|
| CVE-2026-40541 | Aug 28, 2026 |
Synology Chat Server 2.4.5-22148 XSS: Authenticated UI can read/write filesAn improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write arbitrary files and conduct denial-of-service attacks in DSM. |
|
| CVE-2024-47263 | Jun 03, 2026 |
Synology Hyper Backup PT: admin can write files (<4.1.2-4036)An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository webapi component in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users with administrator privileges to write specific files containing non-sensitive information via unspecified vectors. |
|
| CVE-2024-47273 | Jun 03, 2026 |
Path Traversal in Synology Hyper Backup pre-4.1.2-4036 via Backup TaskAn improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functionality in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users to write specific files via unspecified vectors. |
|
| CVE-2022-49036 | Jun 03, 2026 |
Arbitrary Code Exec via Untrusted OpenSSL Config in Active Backup <= 2.5.0-2081An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified vectors. |
|
| CVE-2022-49042 | Jun 03, 2026 |
Synology Hyper Backup Explorer <3.0.1-0156 MinGW DLL Arbitrary Code ExecAn inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via unspecified vectors. |
|
| CVE-2023-52951 | Jun 03, 2026 |
Synology Note Station Client <2.2.4-703: Cleartext Credential TransmissionA cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle attackers to obtain user credential. |
|
| CVE-2026-2237 | May 27, 2026 |
Synology Storage Manager <1.0.1-1100: GET Query Strings Info DisclosureA use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 allows local users on Windows to obtain sensitive information. |
|
| CVE-2025-66593 | May 27, 2026 |
Synology Assistant <7.0.6: Local File Write via Origin ValidationAn origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation. |
|
| CVE-2025-66592 | May 27, 2026 |
Synology Active Backup Prior 3.1.0-4967: Origin Validation File WriteAn origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation. |
|
| CVE-2025-30028 | May 27, 2026 |
Synology Active Backup for Business: Unauth File Read VulnerabilityA vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files. |
|
| CVE-2025-14713 | May 27, 2026 |
Synology C2 Edge Server: Credential Exposure in DSM <1.76.00307An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote attackers to obtain user credentials from the edge server. |
|
| CVE-2025-13593 | May 27, 2026 |
Local File Write in Synology ActiveProtect Agent < v1.1.0-0439Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation. |
|
| CVE-2025-12686 | May 27, 2026 |
Synology BeeStation Manager BSM Buffer Overflow in AdminCenter Before 1.3.2-65648Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStation OS before 1.3.2-65648 allows remote attackers to execute arbitrary code via unspecified vectors. |
|
| CVE-2025-13392 | May 27, 2026 |
Synology DSM SSO Auth Bypass (<=7.2.2, <=7.3.1)Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected) allows remote attackers to bypass authentication with prior knowledge of the distinguished name (DN). |
|
| CVE-2025-13167 | May 27, 2026 |
Synology Contacts XSS via contact form before 1.0.10-20659 - CVE-2025-13167Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functionality in Synology Contacts before 1.0.10-20659 allows remote authenticated users to read or write specific files containing non-sensitive information via unspecified vectors. |
|
| CVE-2025-10466 | May 27, 2026 |
CVE-2025-10466: XSS in Synology Safe Access <1.3.1-0329 (SRM)Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Safe Access in Synology Safe Access before 1.3.1-0329 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information or conduct limited denial-of-service in SRM. |
|
| CVE-2024-47272 | May 27, 2026 |
Synology Surveillance Station 9.2.2 Auth Bypass Limiting File WriteIncorrect authorization vulnerability in IO Module functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors. |
|
| CVE-2024-47271 | May 27, 2026 |
Synology Surveillance Station 9.2.2-11575 IP Speaker cred leak remote adminInsufficiently protected credentials vulnerability in IPSpeaker component in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors. |
|
| CVE-2024-47270 | May 27, 2026 |
Synology Surveillance Station 9.2.2 Improper Permission Preservation (ArchPush)Improper preservation of permissions vulnerability in Archiving Push functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors. |
|
| CVE-2024-47269 | May 27, 2026 |
Synology Surveillance Station <9.2.2: Export Key Cleartext Transmission LeakCleartext transmission of sensitive information vulnerability in Export Key functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors. |
|
| CVE-2024-47268 | May 27, 2026 |
Missing Auth in Synology Surveillance Station AddOns (v<9.2.2-11575 & 9.2.2-9575)Missing authorization vulnerability in AddOns functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors. |
|
| CVE-2024-47267 | May 27, 2026 |
Synology Surveillance Station <=9.2.2 Path Traversal via Archiving PullImproper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Archiving Pull functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors. |
|
| CVE-2024-11399 | May 27, 2026 |
BeeDrive Desktop <=1.3.2: redis-server Files Exposure (CWE-22)Files or directories accessible to external parties vulnerability in redis-server component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to conduct denial-of-service attacks via unspecified vectors. |
|
| CVE-2023-52945 | May 27, 2026 |
Synology BeeDrive <1.3.2-13814: Unctrl Search Path Elem in OpenSSL DLL -> Local Code ExecUncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to execute arbitrary code via unspecified vectors. |
|
| CVE-2021-47961 | Apr 10, 2026 |
Synology SSL VPN Client <1.4.5 plaintext password storage vulnA plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user's PIN code due to insecure storage. This may lead to unauthorized VPN configuration and potential interception of subsequent VPN traffic when combined with user interaction. |
|
| CVE-2021-47960 | Apr 10, 2026 |
Synology SSL VPN Client <1.4.5-0684: HTTP Loopback Disclosure (CVE-2021-47960)A files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access files within the installation directory via a local HTTP server bound to the loopback interface. By leveraging user interaction with a crafted web page, attackers may retrieve sensitive files such as configuration files, certificates, and logs, leading to information disclosure. |
|
| CVE-2026-3091 | Feb 24, 2026 |
Synology Presto Client <2.1.3-0672 UNC Search Path VulnerabilityAn uncontrolled search path element vulnerability in Synology Presto Client before 2.1.3-0672 allows local users to read or write arbitrary files and conduct denial-of-service during installation by placing a malicious DLL in advance in the same directory as the installer. |
|
| CVE-2025-8074 | Dec 04, 2025 |
BeeDrive Desktop <1.4.3: Local User Arbitrary File Write via Origin ValidationOrigin validation error vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.3-13973 allows local users to write arbitrary files with non-sensitive information via unspecified vectors. |
|
| CVE-2025-54160 | Dec 04, 2025 |
Synology BeeDrive <1.4.2-13960 Path Traversal allows local code executionImproper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors. |