Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-13639: Synology DSM allows remote attackers to read/write files
CVE-2026-13639 · published 11 days ago
Summary
Older versions of Synology DiskStation Manager may not generate enough random data during login, letting attackers guess authentication tokens. This can let them read or change any file on the device and even crash the service. Update DSM to the latest firmware version to fix the issue.
What to do
- Update synology diskstation manager (dsm) to version 7.4-90075 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| synology | diskstation manager (dsm) | < 7.4-90075 |
Original advisory text
An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write...
An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.
Severity
9.8
Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-331Insufficient Entropy
Timeline
Published18 Sep 2026
Updated27 Sep 2026
First seen18 Sep 2026
Track software like this
Free during beta