Junglewise Threat Intelligence

CVE-2026-40531: Synology DiskStation Manager integer overflow in File Operation

CVE-2026-40531 · Severity: medium · CVSS 4.3 · Published 2026-09-18

Technologies: Synology DiskStation Manager (DSM). Vendors: Synology.

Executive brief

Synology DiskStation Manager (DSM) is a central operating system for Synology NAS devices that manages storage, files, and user access. A flaw in the File Operation component allows authenticated users to trigger a denial-of-service condition, potentially causing service interruptions for all users accessing the NAS.

Technical details

An integer overflow or wraparound vulnerability (CWE-190) exists in the File Operation component of Synology DSM. The vulnerability requires remote network access and valid user authentication credentials; no special privileges or user interaction is needed. An authenticated attacker can trigger limited denial-of-service attacks by exploiting the integer overflow. Patches are available: DSM 7.2.1-69057-10, DSM 7.2.2-72806-7, and DSM 7.3.2-86009-2 or later.

Affected products

  • Synology DiskStation Manager (DSM) before 7.2.1-69057-10, before 7.2.2-72806-7, before 7.3.2-86009-2

Timeline

  • 2026-04-15: disclosed
  • 2026-04-15: patched: Patches released for DSM 7.2.1, 7.2.2, and 7.3
  • 2026-09-18: advisory

References

Related threats