Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-13684: Synology DSM can let attackers read or write files
CVE-2026-13684 · published 11 days ago
Summary
Versions of Synology DiskStation Manager before the latest updates may let a remote user trick the system into handling data incorrectly. This can lead to unauthorized access to files, changes to data, or the service stopping unexpectedly. Update DSM to the newest version as soon as possible to close this risk.
What to do
- Update synology diskstation manager (dsm) to version 7.4-90075 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| synology | diskstation manager (dsm) | < 7.4-90075 |
Original advisory text
An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to r...
An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.
Severity
9.8
Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-116Improper Encoding or Escaping of Output
Timeline
Published18 Sep 2026
Updated27 Sep 2026
First seen18 Sep 2026
Track software like this
Free during beta