Junglewise Threat Intelligence

CVE-2026-13684: Synology DiskStation Manager improper encoding in SCGI

CVE-2026-13684 · Severity: critical · CVSS 9.8 · Published 2026-09-18

Technologies: Synology DiskStation Manager. Vendors: Synology.

Executive brief

Synology DiskStation Manager is a centralized storage and file management system used in Synology NAS devices. An improper encoding flaw in the SCGI component allows remote attackers without authentication to read or write arbitrary files on affected systems and cause service disruptions, potentially exposing sensitive data or enabling ransomware deployment.

Technical details

CVE-2026-13684 is an improper encoding or escaping of output vulnerability (CWE-116) in the SCGI (Simple Common Gateway Interface) handler of Synology DSM. The vulnerability is network-accessible and requires no authentication, user interaction, or special privileges. Remote attackers can exploit this flaw to read or write arbitrary files and conduct denial-of-service attacks. Patches are available for DSM 7.2.1, 7.2.2, 7.3.2, and 7.4 as specified in the advisory.

Affected products

  • Synology DiskStation Manager 7.2.1 before 7.2.1-69057-12, 7.2.2 before 7.2.2-72806-9, 7.3.2 before 7.3.2-86009-4, 7.4 before 7.4-90075

Timeline

  • 2026-09-18: disclosed: Vulnerability disclosed by Synology and published on NVD
  • 2026-09-18: patched: Patches released for DSM 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, and 7.4-90075 or above

References

Related threats