Executive brief
Synology DiskStation Manager (DSM) is the operating system for Synology NAS storage devices used in enterprises and homes to manage data and backups. A flaw in the Email API's certificate validation allows attackers conducting man-in-the-middle attacks to intercept communications, read or modify files on the NAS, and trigger denial-of-service events. This requires network proximity and user interaction but can bypass encryption protections.
Technical details
CVE-2026-40539 is an improper certificate validation vulnerability (CWE-295) in the Email API component of Synology DSM. The vulnerability allows man-in-the-middle (MITM) attackers to intercept and manipulate Email API communications due to insufficient certificate validation. Attack preconditions include network adjacency and user interaction (UI:R). Successful exploitation enables attackers to read or write arbitrary files on the affected DSM system and launch denial-of-service attacks. Patches are available: DSM 7.2.1-69057-10, DSM 7.2.2-72806-7, and DSM 7.3.2-86009-2 or later.
Affected products
- Synology DiskStation Manager before 7.2.1-69057-10, 7.2.2-72806-7, and 7.3.2-86009-2
Timeline
- 2026-09-18: disclosed: CVE published
- 2026-04-15: advisory: Synology advisory SA_26_06 published
- 2026-04-15: patched: Fixed in DSM 7.2.1-69057-10, 7.2.2-72806-7, and 7.3.2-86009-2