TL;DR
Synology patched eight Synology DSM vulnerabilities in advisory SA_26_13. Two are critical and need no login. Both let a remote attacker read or write files and cause denial of service on DiskStation Manager devices.
- Total: 8 CVEs
- Severity: 2 Critical · 2 High · 2 Medium · 2 Low
- Actively exploited: None confirmed
- Highest severity: 9.8 (Critical · CVSSv3) — CVE-2026-13684
- Action: Apply the latest security updates now
Track every CVE that hits your stack the moment it's exploited.
Get free email alertsNotable CVEs
| CVE | CVSS (CVSSv3) | Fixed in | Status |
|---|---|---|---|
| CVE-2026-13684 | 9.8 | 7.4-90075, 7.3.2-86009-4, 7.2.2-72806-9 (+1) | Not exploited |
| CVE-2026-13639 | 9.8 | 7.4-90075, 7.3.2-86009-4, 7.2.2-72806-9 (+1) | Not exploited |
| CVE-2026-13673 | 8.8 | 7.4-90075, 7.3.2-86009-4, 7.2.2-72806-9 (+1) | Not exploited |
| CVE-2026-6205 | 8.1 | 7.4-90075, 7.3.2-86009-4, 7.2.2-72806-9 (+1) | Not exploited |
| CVE-2026-13635 | 5.3 | 7.4-90075, 7.3.2-86009-4, 7.2.2-72806-9 (+1) | Not exploited |
| CVE-2026-13623 | 4.8 | 7.4-90075, 7.3.2-86009-4, 7.2.2-72806-9 (+1) | Not exploited |
| CVE-2026-13666 | 3.5 | 7.4-90075, 7.3.2-86009-4, 7.2.2-72806-9 (+1) | Not exploited |
| CVE-2026-13683 | 2.7 | 7.4-90075, 7.3.2-86009-4, 7.2.2-72806-9 (+1) | Not exploited |
Why these Synology DSM vulnerabilities matter
DiskStation Manager runs Synology NAS devices worldwide. These boxes hold backups, files, and business data. A remote flaw there puts that storage at direct risk.
Two of these Synology DSM vulnerabilities score a critical CVSS 9.8. Both require no authentication and no user interaction. That combination makes them the top priority in this batch.
How the attacks work
The two critical flaws
CVE-2026-13684 is an output-encoding flaw in the SCGI component. CVE-2026-13639 is an insufficient-entropy flaw in the login logic. In each case, a remote attacker can read or write arbitrary files. Both can also trigger denial-of-service conditions.
The remaining issues
The other six flaws need some level of access. CVE-2026-13673 and CVE-2026-6205 let authenticated users write files through the LDAP and Upload APIs. Lower-rated bugs cover CRLF injection, cross-site scripting, and SQL injection. The XSS and SQL issues require administrator privileges.
Affected versions
The flaws affect DSM 7.2.1, 7.2.2, 7.3, and 7.4. Synology rates the overall advisory as critical. The company reports no active exploitation, and no public proof-of-concept is noted.
Patch and mitigation steps
Update DSM without delay, since Synology lists no workaround. Upgrade to 7.4-90075, 7.3.2-86009-4, 7.2.2-72806-9, or 7.2.1-69057-12 or above. Match the build to your DSM branch. Review the full Synology security advisory SA_26_13 for details. Finally, limit internet exposure of your NAS and restrict admin access.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!