Diskstation Manager Synology Diskstation Manager

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Synology Diskstation Manager.

By the Year

In 2026 there have been 20 vulnerabilities in Synology Diskstation Manager with an average score of 6.1 out of ten. Last year, in 2025 Diskstation Manager had 6 security vulnerabilities published. That is, 14 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.99




Year Vulnerabilities Average Score
2026 20 6.14
2025 6 7.13
2024 1 5.40
2023 2 7.80
2022 18 8.18
2021 21 7.86
2020 7 6.57
2019 13 6.08
2018 13 7.18

It may take a day or so for new Diskstation Manager vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Synology Diskstation Manager Security Vulnerabilities

CVE-2026-40539: Improper Cert Validation in Synology DSM Email API (pre-7.2.1)
CVE-2026-40539 7.1 - High - September 18, 2026

An improper certificate validation vulnerability in Email API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows man-in-the-middle attackers to read or write arbitrary files and conduct denial-of-service attacks.

Improper Certificate Validation

Synology DSM <7.2.2: Brute-Force Auth Allows Limited File Read
CVE-2026-40538 3.7 - Low - September 18, 2026

An improper restriction of excessive authentication attempts vulnerability in Auto block in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to read limited files via brute-force attacks.

Improper Restriction of Excessive Authentication Attempts

DSM Desktop API Path Traversal (7.2.1) Remote File Write
CVE-2026-40535 6.5 - Medium - September 18, 2026

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to write limited files and conduct limited denial-of-service attacks.

Directory traversal

Synology DSM Desktop API Info Disclosure 7.3.2-86009-2 & earlier
CVE-2026-40533 5.3 - Medium - September 18, 2026

An exposure of sensitive information through data queries vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to obtain non-sensitive information.

Exposure of Sensitive Information Through Data Queries

Synology DSM SSRF in PersonMail API before 7.3.2-86009-2
CVE-2026-40537 4.3 - Medium - September 18, 2026

A server-side request forgery (SSRF) vulnerability in PersonMail API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information.

SSRF

Path Traversal in Synology DSM Audio API <7.2.1 Remote Auth
CVE-2026-40536 4.3 - Medium - September 18, 2026

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information.

Directory traversal

Synology DSM XSS in Video API before 7.3.2-86009-2
CVE-2026-40534 5.4 - Medium - September 18, 2026

An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Video API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write limited files when the player is launched.

XSS

Forced Browsing in Wallpaper Path (DSM 7.x<7.2.1) Enables Auth Leak
CVE-2026-40532 6.5 - Medium - September 18, 2026

A direct request ('forced browsing') vulnerability in Wallpaper Path in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain sensitive information.

forced browsing

Integer Overflow in Synology DSM File Op before 7.3.2-86009-2 Enables DoS
CVE-2026-40531 4.3 - Medium - September 18, 2026

An integer overflow or wraparound vulnerability in File Operation in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to conduct limited denial-of-service attacks.

Integer Overflow or Wraparound

Synology DSM pre-7.3.2 SQLi via Sharing API remote auth
CVE-2026-4036 6.5 - Medium - September 18, 2026

An improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain arbitrary sharing files.

SQL Injection

CRLF Injection in Synology DSM <7.2.1-69057-10 allows file read/write
CVE-2026-40530 8 - High - September 18, 2026

An improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks after the system is rebooted.

CRLF Injection

Synology DSM EventScheduler API SQLi <7.2.1/7.2.2/7.3.2/7.4
CVE-2026-13683 2.7 - Low - September 18, 2026

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in EventScheduler API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users with administrator privileges to obtain non-sensitive information.

SQL Injection

Synology DSM 7.2 Theme API XSS before 7.2.1-69057-12
CVE-2026-13623 4.8 - Medium - September 18, 2026

An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Theme API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users with administrator privileges to read or write limited files.

XSS

CRLF Injection in Synology DSM 7.x Sharing API (v<7.2.1,7.2.2,7.3.2,7.4)
CVE-2026-13666 3.5 - Low - September 18, 2026

An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write limited files when a victim clicks a sharing URL.

CRLF Injection

Synology DSM External Control of File Path Vulnerability before 7.2.1-69057-12
CVE-2026-6205 8.1 - High - September 18, 2026

An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write arbitrary files and conduct denial-of-service attacks.

External Control of File Name or Path

Incorrect Perm Assign in Synology DSM LDAP API <7.2.1, 7.2.2, 7.3.2, 7.4
CVE-2026-13673 8.8 - High - September 18, 2026

An incorrect permission assignment for critical resource vulnerability in LDAP API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks.

Incorrect Permission Assignment for Critical Resource

Synology DSM <7.4.1 Auth API XSS Escaping Issue
CVE-2026-13635 5.3 - Medium - September 18, 2026

An improper encoding or escaping of output vulnerability in Auth API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to obtain non-sensitive information.

Output Sanitization

Low Entropy in DSM Login (<7.2.1-69057-12) Enables Remote File Access & DoS
CVE-2026-13639 9.8 - Critical - September 18, 2026

An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.

Insufficient Entropy

SCGI Improper Escaping in Synology DSM <7.4 (pre7.4.0)
CVE-2026-13684 9.8 - Critical - September 18, 2026

An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.

Output Sanitization

Synology DSM SSO Auth Bypass (<=7.2.2, <=7.3.1)
CVE-2025-13392 8.1 - High - May 27, 2026

Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected) allows remote attackers to bypass authentication with prior knowledge of the distinguished name (DN).

Improper Check for Unusual or Exceptional Conditions

Synology DSM WebAPI CVE-2024-5401: Improper Code Resource Control pre-7.1.1-42962-8, pre-7.2.1-69057
CVE-2024-5401 4.3 - Medium - December 04, 2025

Improper control of dynamically-managed code resources vulnerability in WebAPI component in Synology DiskStation Manager (DSM) before 7.1.1-42962-8 and 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote authenticated users to obtain privileges without consent via unspecified vectors.

Improper Control of Dynamically-Managed Code Resources

Out-of-bound write in Synology DSM CGI before 7.2.1 (DoS)
CVE-2024-45539 7.5 - High - December 04, 2025

Out-of-bounds write vulnerability in cgi components in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to conduct denial-of-service attacks via unspecified vectors.

Memory Corruption

Synology DSM WebAPI CSRF CVE-2024-45538 (before 7.2.1/7.2.2)
CVE-2024-45538 9.6 - Critical - December 04, 2025

Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code via unspecified vectors.

Session Riding

Synology DSM 7.2 RCE via sysplugin Daemon XSS
CVE-2024-10441 - March 19, 2025

Improper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allows remote attackers to execute arbitrary code via unspecified vectors.

Output Sanitization

Impr Cert Validation in DSM LDAP (v<7.2) – MITM Auth Hijack
CVE-2024-10444 - March 19, 2025

Improper certificate validation vulnerability in the LDAP utilities in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows man-in-the-middle attackers to hijack the authentication of administrators via unspecified vectors.

Improper Certificate Validation

Unvalidated Cert Allows Rmt Write in Synology BeeStation & DSM <1.1/6.2.4
CVE-2024-10445 - March 19, 2025

Improper certificate validation vulnerability in the update functionality in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allow remote attackers to write limited files via unspecified vectors.

Improper Certificate Validation

DSM Open Redirect via File Acc (pre-v6.2.4,7.0.1,7.1.1,7.2.1)
CVE-2024-0854 5.4 - Medium - January 24, 2024

URL redirection to untrusted site ('Open Redirect') vulnerability in file access component in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-42218-7, 7.1.1-42962-7 and 7.2.1-69057-2 allows remote authenticated users to conduct phishing attacks via unspecified vectors.

Open Redirect

DSM Insufficient Randomness in User Mgmt (pre-7.2-64561)
CVE-2023-2729 7.5 - High - June 13, 2023

Use of insufficiently random values vulnerability in User Management Functionality in Synology DiskStation Manager (DSM) before 7.2-64561 allows remote attackers to obtain user credential via unspecified vectors.

Use of Insufficiently Random Values

Synology DSM 6.2.4,7.0.1,7.1: Uncontrolled path element CVE-2023-0142
CVE-2023-0142 8.1 - High - June 13, 2023

Uncontrolled search path element vulnerability in Backup Management functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-42218-7 and 7.1-42661 allows remote authenticated users with administrator privileges to read or write arbitrary files via unspecified vectors.

DLL preloading

SSRF in Synology DSM Package Center <7.1-42661 for authenticated users
CVE-2022-27622 4.3 - Medium - October 25, 2022

Server-Side Request Forgery (SSRF) vulnerability in Package Center functionality in Synology DiskStation Manager (DSM) before 7.1-42661 allows remote authenticated users to access intranet resources via unspecified vectors.

SSRF

Synology DSM <7.1-42661: Missing Auth in iSCSI Management (CVE-2022-27623)
CVE-2022-27623 9.1 - Critical - October 25, 2022

Missing authentication for critical function vulnerability in iSCSI management functionality in Synology DiskStation Manager (DSM) before 7.1-42661 allows remote attackers to read or write arbitrary files via unspecified vectors.

Missing Authentication for Critical Function

Synology DSM <=7.1.1-42962-2 OOB Decryption Buffer Overflow
CVE-2022-27624 9.8 - Critical - October 20, 2022

A vulnerability regarding improper restriction of operations within the bounds of a memory buffer is found in the packet decryption functionality of Out-of-Band (OOB) Management. This allows remote attackers to execute arbitrary commands via unspecified vectors. The following models with Synology DiskStation Manager (DSM) versions before 7.1.1-42962-2 may be affected: DS3622xs+, FS3410, and HD6500.

Buffer Overflow

Synology DSM<=7.1.1-42962-2 OOB RCE Buffer Overrun in Message Processing
CVE-2022-27625 9.8 - Critical - October 20, 2022

A vulnerability regarding improper restriction of operations within the bounds of a memory buffer is found in the message processing functionality of Out-of-Band (OOB) Management. This allows remote attackers to execute arbitrary commands via unspecified vectors. The following models with Synology DiskStation Manager (DSM) versions before 7.1.1-42962-2 may be affected: DS3622xs+, FS3410, and HD6500.

Buffer Overflow

Race Condition in Synology DSM OOB Mgmt (v<7.1.1) Remote Exec
CVE-2022-27626 8.1 - High - October 20, 2022

A vulnerability regarding concurrent execution using shared resource with improper synchronization ('Race Condition') is found in the session processing functionality of Out-of-Band (OOB) Management. This allows remote attackers to execute arbitrary commands via unspecified vectors. The following models with Synology DiskStation Manager (DSM) versions before 7.1.1-42962-2 may be affected: DS3622xs+, FS3410, and HD6500.

Race Condition

Out-of-Bounds Read in Synology DSM OOB Management - before 7.1.1-42962-2
CVE-2022-3576 7.5 - High - October 20, 2022

A vulnerability regarding out-of-bounds read is found in the session processing functionality of Out-of-Band (OOB) Management. This allows remote attackers to obtain sensitive information via unspecified vectors. The following models with Synology DiskStation Manager (DSM) versions before 7.1.1-42962-2 may be affected: DS3622xs+, FS3410, and HD6500.

Out-of-bounds Read

Synology DSM webapi: OS Command Inject before 7.0.1-42218-3
CVE-2022-27616 7.2 - High - August 03, 2022

Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 7.0.1-42218-3 allows remote authenticated users to execute arbitrary commands via unspecified vectors.

Shell injection

Synology DSM <6.2.4-25553 Task Mgmt OS Command Injection
CVE-2022-22684 8.8 - High - July 28, 2022

Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in task management component in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows remote authenticated users to execute arbitrary commands via unspecified vectors.

Shell injection

Path Traversal in Synology DSM WebAPI <6.2.3-25423 Allows Remote Deletion
CVE-2022-27610 8.1 - High - July 27, 2022

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25423 allows remote authenticated users to delete arbitrary files via unspecified vectors.

Directory traversal

Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in Authentication functionality in Synology DiskStation Manager (DSM) before 6.2.3-25426-3
CVE-2022-22687 9.8 - Critical - March 25, 2022

Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in Authentication functionality in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors.

Classic Buffer Overflow

Improper neutralization of special elements used in a command ('Command Injection') vulnerability in File service functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-2
CVE-2022-22688 8.8 - High - March 25, 2022

Improper neutralization of special elements used in a command ('Command Injection') vulnerability in File service functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-2 allows remote authenticated users to execute arbitrary commands via unspecified vectors.

Command Injection

The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "
CVE-2021-44142 8.8 - High - February 21, 2022

The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root.

Out-of-bounds Read

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2
CVE-2021-43925 9.8 - Critical - February 07, 2022

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers to inject SQL commands via unspecified vectors.

SQL Injection

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2
CVE-2021-43926 9.8 - Critical - February 07, 2022

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers to inject SQL commands via unspecified vectors.

SQL Injection

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Security Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2
CVE-2021-43927 9.8 - Critical - February 07, 2022

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Security Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers to inject SQL commands via unspecified vectors.

SQL Injection

Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in work flow management in Synology DiskStation Manager (DSM) before 7.0.1-42218-2
CVE-2021-43929 5.4 - Medium - February 07, 2022

Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in work flow management in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

XSS

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in support service management in Synology DiskStation Manager (DSM) before 7.0.1-42218-2
CVE-2022-22679 4.9 - Medium - February 07, 2022

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in support service management in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote authenticated users to write arbitrary files via unspecified vectors.

Directory traversal

Exposure of sensitive information to an unauthorized actor vulnerability in Web Server in Synology DiskStation Manager (DSM) before 7.0.1-42218-2
CVE-2022-22680 7.5 - High - February 07, 2022

Exposure of sensitive information to an unauthorized actor vulnerability in Web Server in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers to obtain sensitive information via unspecified vectors.

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3
CVE-2021-29087 7.5 - High - June 23, 2021

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to write arbitrary files via unspecified vectors.

Directory traversal

Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in file sharing management component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3
CVE-2021-29085 7.5 - High - June 23, 2021

Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in file sharing management component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to read arbitrary files via unspecified vectors.

Injection

Exposure of sensitive information to an unauthorized actor vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3
CVE-2021-29086 7.5 - High - June 23, 2021

Exposure of sensitive information to an unauthorized actor vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to obtain sensitive information via unspecified vectors.

Information Disclosure

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Synology Diskstation Manager or by Synology? Click the Watch button to subscribe.

Synology
Vendor

subscribe