Vendor
Synology vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 52 vulnerabilities in Synology: 0 in the last 7 days and 22 in the last 90 days, 4 of them critical and 0 exploited in the wild. The most recent, CVE-2026-6205, was published on 18 September 2026. 5 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 22
- Critical, all time
- 4
- Exploited in the wild
- 0
About Synology
Synology is a Taiwanese corporation that specializes in network-attached storage (NAS) appliances.
Synology technologies
Latest Synology vulnerabilities
- CVE-2026-6205: Synology DiskStation Manager external control of file name or path in Upload APIhighCVSS 8.1EPSS 0.5%
- CVE-2026-4036: Synology DiskStation Manager SQL injection in Sharing APImediumCVSS 6.5EPSS 0.4%
- CVE-2026-40539: Synology DiskStation Manager improper certificate validation in Email APIhighCVSS 7.1EPSS 0.1%
- CVE-2026-40538: Synology DiskStation Manager brute-force attack via insufficient rate limitinglowCVSS 3.7EPSS 0.4%
- CVE-2026-40537: Synology DiskStation Manager SSRF in PersonMail APImediumCVSS 4.3EPSS 0.3%
- CVE-2026-40536: Synology DiskStation Manager path traversal in Audio APImediumCVSS 4.3EPSS 0.4%
- CVE-2026-40535: Synology DiskStation Manager path traversal in Desktop APImediumCVSS 6.5EPSS 0.5%
- CVE-2026-40534: Synology DiskStation Manager cross-site scripting in Video APImediumCVSS 5.4EPSS 0.3%
- CVE-2026-40533: Synology DiskStation Manager information disclosure in Desktop APImediumCVSS 5.3EPSS 0.4%
- CVE-2026-40532: Synology DiskStation Manager forced browsing in Wallpaper PathmediumCVSS 6.5EPSS 0.4%
- CVE-2026-40531: Synology DiskStation Manager integer overflow in File OperationmediumCVSS 4.3EPSS 0.4%
- CVE-2026-40530: Synology DiskStation Manager CRLF injection in User APIhighCVSS 8EPSS 0.5%
- CVE-2026-13684: Synology DiskStation Manager improper encoding in SCGIcriticalCVSS 9.8EPSS 0.6%
- CVE-2026-13683: Synology DiskStation Manager SQL injection in EventScheduler APIlowCVSS 2.7EPSS 0.3%
- CVE-2026-13673: Synology DiskStation Manager incorrect permission assignment in LDAP APIhighCVSS 8.8EPSS 0.4%
- CVE-2026-13666: Synology DiskStation Manager CRLF injection in Sharing APIlowCVSS 3.5EPSS 0.3%
- CVE-2026-13639: Synology DiskStation Manager insufficient entropy in login logiccriticalCVSS 9.8EPSS 0.7%
- CVE-2026-13635: Synology DiskStation Manager improper encoding in Auth APImediumCVSS 5.3EPSS 0.3%
- CVE-2026-13623: Synology DiskStation Manager cross-site scripting in Theme APImediumCVSS 4.8EPSS 0.3%
- CVE-2026-9548: Synology Chat Server XSS in extract domainmediumCVSS 6.5EPSS 0.3%
- CVE-2026-9491: Synology Chat Server SSRF in webhookmediumCVSS 4.3EPSS 0.4%
- CVE-2026-40541: Synology Chat Server cross-site scripting in domain extractioncriticalCVSS 9EPSS 0.5%
- CVE-2024-47273: Synology Hyper Backup path traversal in Backup TaskmediumCVSS 4.3
- CVE-2024-47263: Synology Hyper Backup path traversal in Backup.Repository webapimediumCVSS 4.1
- CVE-2023-52951: Synology Note Station Client cleartext transmission of credentialsmediumCVSS 5.9
Most severe Synology vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-13639: Synology DiskStation Manager insufficient entropy in login logiccriticalCVSS 9.8EPSS 0.7%
- CVE-2026-13684: Synology DiskStation Manager improper encoding in SCGIcriticalCVSS 9.8EPSS 0.6%
- CVE-2025-12686: Synology BeeStation buffer overflow in AdminCentercriticalCVSS 9.8
- CVE-2026-40541: Synology Chat Server cross-site scripting in domain extractioncriticalCVSS 9EPSS 0.5%
- CVE-2026-13673: Synology DiskStation Manager incorrect permission assignment in LDAP APIhighCVSS 8.8EPSS 0.4%
- CVE-2025-30028: Synology Active Backup for Business SQL injection arbitrary file readhighCVSS 8.6
- CVE-2026-6205: Synology DiskStation Manager external control of file name or path in Upload APIhighCVSS 8.1EPSS 0.5%
- CVE-2021-47961: Synology SSL VPN Client plaintext storage of PIN codehighCVSS 8.1EPSS 0.1%
- CVE-2025-13392: Synology DSM authentication bypass in SSOhighCVSS 8.1
- CVE-2026-40530: Synology DiskStation Manager CRLF injection in User APIhighCVSS 8EPSS 0.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 3 | 1 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 19 | 2 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/synology.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Synology vulnerabilities", https://junglewise.ai/threats/vendors/synology, 26 September 2026.