---
schema: 1
kind: vulnerability
title: "CVE-2026-13684 / CVE-2026-13639 — Synology DSM: two unauthenticated CVSS 9.8 flaws (SCGI output-encoding bug, login-logic entropy weakness) allow remote arbitrary file read/write and denial-of-service with no credentials"
headline: "Synology's own advisory implies trivial exploitation for two unauthenticated CVSS 9.8 DSM flaws, with no mitigation available"
summary: >
  Synology disclosed CVE-2026-13684 (SCGI output-encoding bug) and CVE-2026-13639
  (insufficient login-logic entropy), both CVSS 9.8 and exploitable by a remote,
  unauthenticated attacker to read or write arbitrary files on a DiskStation NAS or
  cause denial-of-service, alongside two lower-severity authenticated-only flaws in the
  same advisory. Fixed in DSM 7.4-90075, 7.3.2-86009-4, 7.2.2-72806-9 and
  7.2.1-69057-12, with no mitigation for the unauthenticated pair; no exploitation is
  confirmed yet, but the vendor's own description implies the flaws are trivial to
  exploit.
discovered_at: "2026-09-22T04:33:00Z"
updated_at: null
event_date: "2026-09-18"
run_id: 2026-09-22T0410Z-intel
priority: high
immediate_action: null
tags: [vulnerabilities, path-traversal, pre-auth, patch-available]
regions: [global]
sectors: [public-sector]
entities: []
techniques: [T1190, T1005]
affected_products: ["Synology DiskStation Manager (DSM)"]
cves:
  - id: CVE-2026-13684
    cvss: "9.8"
    epss: "0.00455"
    type: path-traversal
    vector: zero-click
    auth: pre-auth
    status: [patch-available]
    affected: "DSM before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075"
    fixed: "7.4-90075 / 7.3.2-86009-4 / 7.2.2-72806-9 / 7.2.1-69057-12"
  - id: CVE-2026-13639
    cvss: "9.8"
    epss: "0.00505"
    type: logic-flaw
    vector: zero-click
    auth: pre-auth
    status: [patch-available]
    affected: "DSM before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075"
    fixed: "7.4-90075 / 7.3.2-86009-4 / 7.2.2-72806-9 / 7.2.1-69057-12"
  - id: CVE-2026-13673
    cvss: "8.8"
    epss: "0.00306"
    type: path-traversal
    vector: zero-click
    auth: post-auth
    status: [patch-available]
    affected: "DSM before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075"
    fixed: "7.4-90075 / 7.3.2-86009-4 / 7.2.2-72806-9 / 7.2.1-69057-12"
  - id: CVE-2026-6205
    cvss: "8.1"
    epss: "0.00318"
    type: path-traversal
    vector: zero-click
    auth: post-auth
    status: [patch-available]
    affected: "DSM before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075"
    fixed: "7.4-90075 / 7.3.2-86009-4 / 7.2.2-72806-9 / 7.2.1-69057-12"
sources:
  - url: "https://www.synology.com/en-global/security/advisory/Synology_SA_26_13"
    publisher: "Synology PSIRT"
    date: "2026-09-18"
    role: primary
  - url: "https://security-hub.ncsc.admin.ch/#/posts/12960"
    publisher: "NCSC Switzerland (Cyber Security Hub)"
    date: "2026-09-21"
    role: corroborating
  - url: "https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1209/"
    publisher: "CERT-FR (ANSSI)"
    date: "2026-09-21"
    role: corroborating
  - url: "https://www.heise.de/news/Jetzt-aktualisieren-Angreifer-konnten-beliebige-Daten-von-Synology-NAS-auslesen-11458757.html"
    publisher: "heise online"
    date: "2026-09-18"
    role: corroborating
closed_sources: []
evidence:
  - quote: "An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks."
    publisher: "Synology PSIRT"
  - quote: "Successful exploitation allows unauthenticated attackers to read and write arbitrary files, or disrupt NAS services via denial-of-service attacks."
    publisher: "NCSC Switzerland (Cyber Security Hub)"
  - quote: "The terse description of the flaws on Synology's advisory page is likely to quickly draw ransomware authors and other criminals, since exploitation is, according to Synology, very easy."
    original: "Die knappe Beschreibung der Lücken auf der Synology-Hinweisseite dürfte Ransomware-Autoren und andere Kriminelle zügig auf den Plan rufen, denn ihre Ausnutzung ist nach Synologys Angaben sehr einfach."
    publisher: "heise online (translated from German)"
verification: multi-source
sourcing_note: "Synology's own PSIRT advisory is the sole source of the technical facts; NCSC Switzerland and CERT-FR relay that same advisory rather than independently assessing it, so credibility reflects one assessor with several publishers. heise online adds independent risk commentary on top of the vendor's own wording. CERT-FR's advisory lists remote code execution among the risk categories for its full eight-CVE bundle; the four CVEs this entry covers are typed from each CVE's own per-flaw description in Synology's advisory and NVD, none of which states code execution — none of the other four CVEs in the bundle states it either, so the risk category's basis is not established by any source this entry cites."
confidence: high
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 2
watchlist_hit: false
actions:
  - "Patch every Synology DSM instance to its line's fixed build (7.4-90075 / 7.3.2-86009-4 / 7.2.2-72806-9 / 7.2.1-69057-12) now — there is no mitigation for CVE-2026-13684/CVE-2026-13639 short of the update, and any device left on an older build with the DSM management port reachable from outside its local network should be treated as exposed until patched."
updates: []
migrated_from: null
---

Synology disclosed eight CVEs in DiskStation Manager (DSM) on 2026-09-18 (Synology-SA-26:13); two are unauthenticated and rated Critical, CVSS 9.8 (AV:N/AC:L/PR:N/UI:N, full confidentiality/integrity/availability impact): CVE-2026-13684 (CWE-116, improper output encoding/escaping in the SCGI component) and CVE-2026-13639 (CWE-331, insufficient entropy in the login logic). Each lets a remote, unauthenticated attacker read or write arbitrary files on the NAS and cause denial-of-service ([Synology PSIRT, 2026-09-18](https://www.synology.com/en-global/security/advisory/Synology_SA_26_13)). Two further flaws in the same advisory need only a low-privileged authenticated session: CVE-2026-13673 (CVSS 8.8, CWE-732, incorrect permission assignment in the LDAP API), which also reaches arbitrary file read/write and denial-of-service, and CVE-2026-6205 (CVSS 8.1, CWE-73, external control of file name/path in the Upload API), which reaches arbitrary file write (not read) and denial-of-service ([Synology PSIRT, 2026-09-18](https://www.synology.com/en-global/security/advisory/Synology_SA_26_13)). All four are fixed in DSM 7.4-90075, 7.3.2-86009-4, 7.2.2-72806-9 and 7.2.1-69057-12; Synology lists no mitigation for the unauthenticated pair ([Synology PSIRT, 2026-09-18](https://www.synology.com/en-global/security/advisory/Synology_SA_26_13)).

NCSC Switzerland's Cyber Security Hub advisory, published 2026-09-21, three days after Synology's original release, records exploitation status as unknown ([NCSC Switzerland, 2026-09-21](https://security-hub.ncsc.admin.ch/#/posts/12960)); CERT-FR's advisory, published the same day, relays the same affected-version detail without commenting on exploitation status ([CERT-FR, 2026-09-21](https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1209/)). This is a newly disclosed, not-yet-exploited pair of pre-auth critical flaws. heise online's coverage, published the same day as Synology's advisory, explicitly flags the risk profile: "the terse description of the flaws on Synology's advisory page is likely to quickly draw ransomware authors and other criminals, since exploitation is, according to Synology, very easy" (translated from German) ([heise online, 2026-09-18](https://www.heise.de/news/Jetzt-aktualisieren-Angreifer-konnten-beliebige-Daten-von-Synology-NAS-auslesen-11458757.html)). Synology NAS devices are commonly configured with remote or WAN-facing access for off-site backup and file-sync use cases, so the unauthenticated pair's true internet exposure is a function of each deployment's own remote-access configuration rather than a DSM default.

**Detection:** the SCGI and login-logic surfaces sit behind the standard DSM web-management port, so unexpected file reads or writes outside a session's own storage scope, or unauthenticated requests reaching the SCGI/login endpoints from outside the expected administrative source range, are the sharpest signal; log ingestion should treat any file-integrity change on system configuration paths that does not correlate with an authenticated admin session as suspicious. Hardening: apply the update immediately rather than waiting for the next maintenance window, given the vendor's own trivial-exploitability framing; confirm the running build against the advisory's affected-products table, since several readers noted the advisory targets older DSM baselines and an estate already on the latest supported build (DSM 7.4.1-90080 has been current since July 2026) may already be unaffected (translated from German) ([heise online, 2026-09-18](https://www.heise.de/news/Jetzt-aktualisieren-Angreifer-konnten-beliebige-Daten-von-Synology-NAS-auslesen-11458757.html)); where remote or WAN-facing access is enabled, restrict it to a VPN or IP allowlist until the patch is confirmed applied fleet-wide.
