CTIPilot
← Back to the live brief
HIGHCVE-2026-13684 +3NATOA2vulnerability

CVE-2026-13684 / CVE-2026-13639, Synology DSM: two unauthenticated CVSS 9.8 flaws (SCGI output-encoding bug, login-logic entropy weakness) allow remote arbitrary file read/write and denial-of-service with no credentials

Synology's own advisory implies trivial exploitation for two unauthenticated CVSS 9.8 DSM flaws, with no mitigation available

Defender actions

  • Patch every Synology DSM instance to its line's fixed build (7.4-90075 / 7.3.2-86009-4 / 7.2.2-72806-9 / 7.2.1-69057-12) now; there is no mitigation for CVE-2026-13684/CVE-2026-13639 short of the update, and any device left on an older build with the DSM management port reachable from outside its local network should be treated as exposed until patched.

Analysis

Synology disclosed eight CVEs in DiskStation Manager (DSM) on 2026-09-18 (Synology-SA-26:13); two are unauthenticated and rated Critical, CVSS 9.8 (AV:N/AC:L/PR:N/UI:N, full confidentiality/integrity/availability impact): CVE-2026-13684 (CWE-116, improper output encoding/escaping in the SCGI component) and CVE-2026-13639 (CWE-331, insufficient entropy in the login logic). Each lets a remote, unauthenticated attacker read or write arbitrary files on the NAS and cause denial-of-service (Synology PSIRT, 2026-09-18). Two further flaws in the same advisory need only a low-privileged authenticated session: CVE-2026-13673 (CVSS 8.8, CWE-732, incorrect permission assignment in the LDAP API), which also reaches arbitrary file read/write and denial-of-service, and CVE-2026-6205 (CVSS 8.1, CWE-73, external control of file name/path in the Upload API), which reaches arbitrary file write (not read) and denial-of-service (Synology PSIRT, 2026-09-18). All four are fixed in DSM 7.4-90075, 7.3.2-86009-4, 7.2.2-72806-9 and 7.2.1-69057-12; Synology lists no mitigation for the unauthenticated pair (Synology PSIRT, 2026-09-18).

NCSC Switzerland's Cyber Security Hub advisory, published 2026-09-21, three days after Synology's original release, records exploitation status as unknown (NCSC Switzerland, 2026-09-21); CERT-FR's advisory, published the same day, relays the same affected-version detail without commenting on exploitation status (CERT-FR, 2026-09-21). This is a newly disclosed, not-yet-exploited pair of pre-auth critical flaws. heise online's coverage, published the same day as Synology's advisory, explicitly flags the risk profile: "the terse description of the flaws on Synology's advisory page is likely to quickly draw ransomware authors and other criminals, since exploitation is, according to Synology, very easy" (translated from German) (heise online, 2026-09-18). Synology NAS devices are commonly configured with remote or WAN-facing access for off-site backup and file-sync use cases, so the unauthenticated pair's true internet exposure is a function of each deployment's own remote-access configuration rather than a DSM default.

Cited evidence

An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.

Synology PSIRT 2026-09-18

Successful exploitation allows unauthenticated attackers to read and write arbitrary files, or disrupt NAS services via denial-of-service attacks.

NCSC Switzerland (Cyber Security Hub) 2026-09-21

The terse description of the flaws on Synology's advisory page is likely to quickly draw ransomware authors and other criminals, since exploitation is, according to Synology, very easy.

heise online (translated from German)

Sources4

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.