Junglewise Threat Intelligence

CVE-2026-40539: Synology DiskStation Manager improper certificate validation in Email API

CVE-2026-40539 · Severity: high · CVSS 7.1 · Published 2026-09-18

Technologies: Synology DiskStation Manager. Vendors: Synology.

Executive brief

Synology DiskStation Manager (DSM) is the operating system for Synology NAS storage devices used in enterprises and homes to manage data and backups. A flaw in the Email API's certificate validation allows attackers conducting man-in-the-middle attacks to intercept communications, read or modify files on the NAS, and trigger denial-of-service events. This requires network proximity and user interaction but can bypass encryption protections.

Technical details

CVE-2026-40539 is an improper certificate validation vulnerability (CWE-295) in the Email API component of Synology DSM. The vulnerability allows man-in-the-middle (MITM) attackers to intercept and manipulate Email API communications due to insufficient certificate validation. Attack preconditions include network adjacency and user interaction (UI:R). Successful exploitation enables attackers to read or write arbitrary files on the affected DSM system and launch denial-of-service attacks. Patches are available: DSM 7.2.1-69057-10, DSM 7.2.2-72806-7, and DSM 7.3.2-86009-2 or later.

Affected products

  • Synology DiskStation Manager before 7.2.1-69057-10, 7.2.2-72806-7, and 7.3.2-86009-2

Timeline

  • 2026-09-18: disclosed: CVE published
  • 2026-04-15: advisory: Synology advisory SA_26_06 published
  • 2026-04-15: patched: Fixed in DSM 7.2.1-69057-10, 7.2.2-72806-7, and 7.3.2-86009-2

References

Related threats