CVE-2026-13639 is a vulnerability in Synology Diskstation Manager
Published on September 18, 2026
An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.
Vulnerability Analysis
CVE-2026-13639 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.
Weakness Type
Insufficient Entropy
The software uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.
Products Associated with CVE-2026-13639
Want to know whenever a new CVE is published for Synology Diskstation Manager? stack.watch will email you.
Affected Versions
Synology DiskStation Manager (DSM):- Version 7.4 and below 7.4-90075 is affected.
- Version 7.3.2 and below 7.3.2-86009-4 is affected.
- Version 7.2.2 and below 7.2.2-72806-9 is affected.
- Version 7.2.1 and below 7.2.1-69057-12 is affected.
- Before 7.2.1 is unknown.