Synology Diskstation Manager
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Synology Diskstation Manager.
By the Year
In 2026 there have been 20 vulnerabilities in Synology Diskstation Manager with an average score of 6.1 out of ten. Last year, in 2025 Diskstation Manager had 6 security vulnerabilities published. That is, 14 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.99
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 20 | 6.14 |
| 2025 | 6 | 7.13 |
| 2024 | 1 | 5.40 |
| 2023 | 2 | 7.80 |
| 2022 | 18 | 8.18 |
| 2021 | 21 | 7.86 |
| 2020 | 7 | 6.57 |
| 2019 | 13 | 6.08 |
| 2018 | 13 | 7.18 |
It may take a day or so for new Diskstation Manager vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Synology Diskstation Manager Security Vulnerabilities
CVE-2026-40539: Improper Cert Validation in Synology DSM Email API (pre-7.2.1)
CVE-2026-40539
7.1 - High
- September 18, 2026
An improper certificate validation vulnerability in Email API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows man-in-the-middle attackers to read or write arbitrary files and conduct denial-of-service attacks.
Improper Certificate Validation
Synology DSM <7.2.2: Brute-Force Auth Allows Limited File Read
CVE-2026-40538
3.7 - Low
- September 18, 2026
An improper restriction of excessive authentication attempts vulnerability in Auto block in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to read limited files via brute-force attacks.
Improper Restriction of Excessive Authentication Attempts
DSM Desktop API Path Traversal (7.2.1) Remote File Write
CVE-2026-40535
6.5 - Medium
- September 18, 2026
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to write limited files and conduct limited denial-of-service attacks.
Directory traversal
Synology DSM Desktop API Info Disclosure 7.3.2-86009-2 & earlier
CVE-2026-40533
5.3 - Medium
- September 18, 2026
An exposure of sensitive information through data queries vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to obtain non-sensitive information.
Exposure of Sensitive Information Through Data Queries
Synology DSM SSRF in PersonMail API before 7.3.2-86009-2
CVE-2026-40537
4.3 - Medium
- September 18, 2026
A server-side request forgery (SSRF) vulnerability in PersonMail API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information.
SSRF
Path Traversal in Synology DSM Audio API <7.2.1 Remote Auth
CVE-2026-40536
4.3 - Medium
- September 18, 2026
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information.
Directory traversal
Synology DSM XSS in Video API before 7.3.2-86009-2
CVE-2026-40534
5.4 - Medium
- September 18, 2026
An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Video API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write limited files when the player is launched.
XSS
Forced Browsing in Wallpaper Path (DSM 7.x<7.2.1) Enables Auth Leak
CVE-2026-40532
6.5 - Medium
- September 18, 2026
A direct request ('forced browsing') vulnerability in Wallpaper Path in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain sensitive information.
forced browsing
Integer Overflow in Synology DSM File Op before 7.3.2-86009-2 Enables DoS
CVE-2026-40531
4.3 - Medium
- September 18, 2026
An integer overflow or wraparound vulnerability in File Operation in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to conduct limited denial-of-service attacks.
Integer Overflow or Wraparound
Synology DSM pre-7.3.2 SQLi via Sharing API remote auth
CVE-2026-4036
6.5 - Medium
- September 18, 2026
An improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain arbitrary sharing files.
SQL Injection
CRLF Injection in Synology DSM <7.2.1-69057-10 allows file read/write
CVE-2026-40530
8 - High
- September 18, 2026
An improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks after the system is rebooted.
CRLF Injection
Synology DSM EventScheduler API SQLi <7.2.1/7.2.2/7.3.2/7.4
CVE-2026-13683
2.7 - Low
- September 18, 2026
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in EventScheduler API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users with administrator privileges to obtain non-sensitive information.
SQL Injection
Synology DSM 7.2 Theme API XSS before 7.2.1-69057-12
CVE-2026-13623
4.8 - Medium
- September 18, 2026
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Theme API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users with administrator privileges to read or write limited files.
XSS
CRLF Injection in Synology DSM 7.x Sharing API (v<7.2.1,7.2.2,7.3.2,7.4)
CVE-2026-13666
3.5 - Low
- September 18, 2026
An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write limited files when a victim clicks a sharing URL.
CRLF Injection
Synology DSM External Control of File Path Vulnerability before 7.2.1-69057-12
CVE-2026-6205
8.1 - High
- September 18, 2026
An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write arbitrary files and conduct denial-of-service attacks.
External Control of File Name or Path
Incorrect Perm Assign in Synology DSM LDAP API <7.2.1, 7.2.2, 7.3.2, 7.4
CVE-2026-13673
8.8 - High
- September 18, 2026
An incorrect permission assignment for critical resource vulnerability in LDAP API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks.
Incorrect Permission Assignment for Critical Resource
Synology DSM <7.4.1 Auth API XSS Escaping Issue
CVE-2026-13635
5.3 - Medium
- September 18, 2026
An improper encoding or escaping of output vulnerability in Auth API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to obtain non-sensitive information.
Output Sanitization
Low Entropy in DSM Login (<7.2.1-69057-12) Enables Remote File Access & DoS
CVE-2026-13639
9.8 - Critical
- September 18, 2026
An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.
Insufficient Entropy
SCGI Improper Escaping in Synology DSM <7.4 (pre7.4.0)
CVE-2026-13684
9.8 - Critical
- September 18, 2026
An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.
Output Sanitization
Synology DSM SSO Auth Bypass (<=7.2.2, <=7.3.1)
CVE-2025-13392
8.1 - High
- May 27, 2026
Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected) allows remote attackers to bypass authentication with prior knowledge of the distinguished name (DN).
Improper Check for Unusual or Exceptional Conditions
Synology DSM WebAPI CVE-2024-5401: Improper Code Resource Control pre-7.1.1-42962-8, pre-7.2.1-69057
CVE-2024-5401
4.3 - Medium
- December 04, 2025
Improper control of dynamically-managed code resources vulnerability in WebAPI component in Synology DiskStation Manager (DSM) before 7.1.1-42962-8 and 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote authenticated users to obtain privileges without consent via unspecified vectors.
Improper Control of Dynamically-Managed Code Resources
Out-of-bound write in Synology DSM CGI before 7.2.1 (DoS)
CVE-2024-45539
7.5 - High
- December 04, 2025
Out-of-bounds write vulnerability in cgi components in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to conduct denial-of-service attacks via unspecified vectors.
Memory Corruption
Synology DSM WebAPI CSRF CVE-2024-45538 (before 7.2.1/7.2.2)
CVE-2024-45538
9.6 - Critical
- December 04, 2025
Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code via unspecified vectors.
Session Riding
Synology DSM 7.2 RCE via sysplugin Daemon XSS
CVE-2024-10441
- March 19, 2025
Improper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allows remote attackers to execute arbitrary code via unspecified vectors.
Output Sanitization
Impr Cert Validation in DSM LDAP (v<7.2) – MITM Auth Hijack
CVE-2024-10444
- March 19, 2025
Improper certificate validation vulnerability in the LDAP utilities in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows man-in-the-middle attackers to hijack the authentication of administrators via unspecified vectors.
Improper Certificate Validation
Unvalidated Cert Allows Rmt Write in Synology BeeStation & DSM <1.1/6.2.4
CVE-2024-10445
- March 19, 2025
Improper certificate validation vulnerability in the update functionality in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allow remote attackers to write limited files via unspecified vectors.
Improper Certificate Validation
DSM Open Redirect via File Acc (pre-v6.2.4,7.0.1,7.1.1,7.2.1)
CVE-2024-0854
5.4 - Medium
- January 24, 2024
URL redirection to untrusted site ('Open Redirect') vulnerability in file access component in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-42218-7, 7.1.1-42962-7 and 7.2.1-69057-2 allows remote authenticated users to conduct phishing attacks via unspecified vectors.
Open Redirect
DSM Insufficient Randomness in User Mgmt (pre-7.2-64561)
CVE-2023-2729
7.5 - High
- June 13, 2023
Use of insufficiently random values vulnerability in User Management Functionality in Synology DiskStation Manager (DSM) before 7.2-64561 allows remote attackers to obtain user credential via unspecified vectors.
Use of Insufficiently Random Values
Synology DSM 6.2.4,7.0.1,7.1: Uncontrolled path element CVE-2023-0142
CVE-2023-0142
8.1 - High
- June 13, 2023
Uncontrolled search path element vulnerability in Backup Management functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-42218-7 and 7.1-42661 allows remote authenticated users with administrator privileges to read or write arbitrary files via unspecified vectors.
DLL preloading
SSRF in Synology DSM Package Center <7.1-42661 for authenticated users
CVE-2022-27622
4.3 - Medium
- October 25, 2022
Server-Side Request Forgery (SSRF) vulnerability in Package Center functionality in Synology DiskStation Manager (DSM) before 7.1-42661 allows remote authenticated users to access intranet resources via unspecified vectors.
SSRF
Synology DSM <7.1-42661: Missing Auth in iSCSI Management (CVE-2022-27623)
CVE-2022-27623
9.1 - Critical
- October 25, 2022
Missing authentication for critical function vulnerability in iSCSI management functionality in Synology DiskStation Manager (DSM) before 7.1-42661 allows remote attackers to read or write arbitrary files via unspecified vectors.
Missing Authentication for Critical Function
Synology DSM <=7.1.1-42962-2 OOB Decryption Buffer Overflow
CVE-2022-27624
9.8 - Critical
- October 20, 2022
A vulnerability regarding improper restriction of operations within the bounds of a memory buffer is found in the packet decryption functionality of Out-of-Band (OOB) Management. This allows remote attackers to execute arbitrary commands via unspecified vectors. The following models with Synology DiskStation Manager (DSM) versions before 7.1.1-42962-2 may be affected: DS3622xs+, FS3410, and HD6500.
Buffer Overflow
Synology DSM<=7.1.1-42962-2 OOB RCE Buffer Overrun in Message Processing
CVE-2022-27625
9.8 - Critical
- October 20, 2022
A vulnerability regarding improper restriction of operations within the bounds of a memory buffer is found in the message processing functionality of Out-of-Band (OOB) Management. This allows remote attackers to execute arbitrary commands via unspecified vectors. The following models with Synology DiskStation Manager (DSM) versions before 7.1.1-42962-2 may be affected: DS3622xs+, FS3410, and HD6500.
Buffer Overflow
Race Condition in Synology DSM OOB Mgmt (v<7.1.1) Remote Exec
CVE-2022-27626
8.1 - High
- October 20, 2022
A vulnerability regarding concurrent execution using shared resource with improper synchronization ('Race Condition') is found in the session processing functionality of Out-of-Band (OOB) Management. This allows remote attackers to execute arbitrary commands via unspecified vectors. The following models with Synology DiskStation Manager (DSM) versions before 7.1.1-42962-2 may be affected: DS3622xs+, FS3410, and HD6500.
Race Condition
Out-of-Bounds Read in Synology DSM OOB Management - before 7.1.1-42962-2
CVE-2022-3576
7.5 - High
- October 20, 2022
A vulnerability regarding out-of-bounds read is found in the session processing functionality of Out-of-Band (OOB) Management. This allows remote attackers to obtain sensitive information via unspecified vectors. The following models with Synology DiskStation Manager (DSM) versions before 7.1.1-42962-2 may be affected: DS3622xs+, FS3410, and HD6500.
Out-of-bounds Read
Synology DSM webapi: OS Command Inject before 7.0.1-42218-3
CVE-2022-27616
7.2 - High
- August 03, 2022
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 7.0.1-42218-3 allows remote authenticated users to execute arbitrary commands via unspecified vectors.
Shell injection
Synology DSM <6.2.4-25553 Task Mgmt OS Command Injection
CVE-2022-22684
8.8 - High
- July 28, 2022
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in task management component in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows remote authenticated users to execute arbitrary commands via unspecified vectors.
Shell injection
Path Traversal in Synology DSM WebAPI <6.2.3-25423 Allows Remote Deletion
CVE-2022-27610
8.1 - High
- July 27, 2022
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25423 allows remote authenticated users to delete arbitrary files via unspecified vectors.
Directory traversal
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in Authentication functionality in Synology DiskStation Manager (DSM) before 6.2.3-25426-3
CVE-2022-22687
9.8 - Critical
- March 25, 2022
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in Authentication functionality in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors.
Classic Buffer Overflow
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in File service functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-2
CVE-2022-22688
8.8 - High
- March 25, 2022
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in File service functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-2 allows remote authenticated users to execute arbitrary commands via unspecified vectors.
Command Injection
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "
CVE-2021-44142
8.8 - High
- February 21, 2022
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root.
Out-of-bounds Read
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2
CVE-2021-43925
9.8 - Critical
- February 07, 2022
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers to inject SQL commands via unspecified vectors.
SQL Injection
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2
CVE-2021-43926
9.8 - Critical
- February 07, 2022
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers to inject SQL commands via unspecified vectors.
SQL Injection
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Security Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2
CVE-2021-43927
9.8 - Critical
- February 07, 2022
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Security Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers to inject SQL commands via unspecified vectors.
SQL Injection
Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in work flow management in Synology DiskStation Manager (DSM) before 7.0.1-42218-2
CVE-2021-43929
5.4 - Medium
- February 07, 2022
Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in work flow management in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
XSS
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in support service management in Synology DiskStation Manager (DSM) before 7.0.1-42218-2
CVE-2022-22679
4.9 - Medium
- February 07, 2022
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in support service management in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote authenticated users to write arbitrary files via unspecified vectors.
Directory traversal
Exposure of sensitive information to an unauthorized actor vulnerability in Web Server in Synology DiskStation Manager (DSM) before 7.0.1-42218-2
CVE-2022-22680
7.5 - High
- February 07, 2022
Exposure of sensitive information to an unauthorized actor vulnerability in Web Server in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers to obtain sensitive information via unspecified vectors.
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3
CVE-2021-29087
7.5 - High
- June 23, 2021
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to write arbitrary files via unspecified vectors.
Directory traversal
Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in file sharing management component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3
CVE-2021-29085
7.5 - High
- June 23, 2021
Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in file sharing management component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to read arbitrary files via unspecified vectors.
Injection
Exposure of sensitive information to an unauthorized actor vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3
CVE-2021-29086
7.5 - High
- June 23, 2021
Exposure of sensitive information to an unauthorized actor vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to obtain sensitive information via unspecified vectors.
Information Disclosure
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Synology Diskstation Manager or by Synology? Click the Watch button to subscribe.