CTIPilot

Synology DiskStation Manager (DSM)

product · product:synology-diskstation-manager-dsm

Coverage timeline
1
first 2026-09-22 → last 2026-09-22
Peak priority
high
1 high
Sources cited
4
4 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
4
see Co-occurring entities below
ATT&CK techniques
2
pinned v19.2 · see below

Hunting pivots

Releases covered
Synology DiskStation Manager (DSM)
ATT&CK techniques

ATT&CK techniques

2 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-09-22/cve-2026-13684-synology-dsm-unauth-file-read-write · ATT&CK page ↗

Collection TA0009

T1005Data from Local System×1

Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.

Evidence: 2026-09-22/cve-2026-13684-synology-dsm-unauth-file-read-write · ATT&CK page ↗

Story timeline

  1. 2026-09-22CVE-2026-13684 / CVE-2026-13639, Synology DSM: two unauthenticated CVSS 9.8 flaws (SCGI output-encoding bug, login-logic entropy weakness) allow remote arbitrary file read/write and denial-of-service with no credentials
    trending-vulnerabilitiesSynology's own advisory implies trivial exploitation for two unauthenticated CVSS 9.8 DSM flaws, with no mitigation available

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • cert.ssi.gouv.fr1 (25%)
  • heise.de1 (25%)
  • security-hub.ncsc.admin.ch1 (25%)
  • synology.com1 (25%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Synology DiskStation Manager (DSM) (1)

2026-09-22 · view entry permalink →

CVE-2026-13684 / CVE-2026-13639, Synology DSM: two unauthenticated CVSS 9.8 flaws (SCGI output-encoding bug, login-logic entropy weakness) allow remote arbitrary file read/write and denial-of-service with no credentials

Synology disclosed eight CVEs in DiskStation Manager (DSM) on 2026-09-18 (Synology-SA-26:13); two are unauthenticated and rated Critical, CVSS 9.8 (AV:N/AC:L/PR:N/UI:N, full confidentiality/integrity/availability impact): CVE-2026-13684 (CWE-116, improper output encoding/escaping in the SCGI component) and CVE-2026-13639 (CWE-331, insufficient entropy in the login logic). Each lets a remote, unauthenticated attacker read or write arbitrary files on the NAS and cause denial-of-service (Synology PSIRT, 2026-09-18). Two further flaws in the same advisory need only a low-privileged authenticated session: CVE-2026-13673 (CVSS 8.8, CWE-732, incorrect permission assignment in the LDAP API), which also reaches arbitrary file read/write and denial-of-service, and CVE-2026-6205 (CVSS 8.1, CWE-73, external control of file name/path in the Upload API), which reaches arbitrary file write (not read) and denial-of-service (Synology PSIRT, 2026-09-18). All four are fixed in DSM 7.4-90075, 7.3.2-86009-4, 7.2.2-72806-9 and 7.2.1-69057-12; Synology lists no mitigation for the unauthenticated pair (Synology PSIRT, 2026-09-18).

NCSC Switzerland's Cyber Security Hub advisory, published 2026-09-21, three days after Synology's original release, records exploitation status as unknown (NCSC Switzerland, 2026-09-21); CERT-FR's advisory, published the same day, relays the same affected-version detail without commenting on exploitation status (CERT-FR, 2026-09-21). This is a newly disclosed, not-yet-exploited pair of pre-auth critical flaws. heise online's coverage, published the same day as Synology's advisory, explicitly flags the risk profile: "the terse description of the flaws on Synology's advisory page is likely to quickly draw ransomware authors and other criminals, since exploitation is, according to Synology, very easy" (translated from German) (heise online, 2026-09-18). Synology NAS devices are commonly configured with remote or WAN-facing access for off-site backup and file-sync use cases, so the unauthenticated pair's true internet exposure is a function of each deployment's own remote-access configuration rather than a DSM default.

An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.

Synology PSIRT 2026-09-18

Successful exploitation allows unauthenticated attackers to read and write arbitrary files, or disrupt NAS services via denial-of-service attacks.

NCSC Switzerland (Cyber Security Hub) 2026-09-21

The terse description of the flaws on Synology's advisory page is likely to quickly draw ransomware authors and other criminals, since exploitation is, according to Synology, very easy.

heise online (translated from German)
vulnerability22 Sep 04:33Zmulti-sourceOpen finding ↗