Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-13639: Synology DSM allows remote attackers to read/write files

CVE-2026-13639 · published 11 days ago
Summary

Older versions of Synology DiskStation Manager may not generate enough random data during login, letting attackers guess authentication tokens. This can let them read or change any file on the device and even crash the service. Update DSM to the latest firmware version to fix the issue.

What to do
  • Update synology diskstation manager (dsm) to version 7.4-90075 or later.
Affected software
VendorProductAffected versions
synology diskstation manager (dsm) < 7.4-90075
Original advisory text
An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write...
An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.
Severity
9.8 Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-331Insufficient Entropy
Timeline
Published18 Sep 2026
Updated27 Sep 2026
First seen18 Sep 2026
Sources
CVE-2026-13639 · MITRE
Track software like this
Free during beta