- CVE-2026-13639 CRITICAL CVSS 9.8 -
NVD: An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.
This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure; CVSS 9.8 (CRITICAL); EPSS percentile 50; sources: NVD.
- CVE-2026-13684 CRITICAL CVSS 9.8 -
NVD: An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service...
This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure; CVSS 9.8 (CRITICAL); EPSS percentile 46; sources: NVD.
- CVE-2026-13673 HIGH CVSS 8.8 -
NVD: An incorrect permission assignment for critical resource vulnerability in LDAP API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to read or write arbitrary files and...
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary; CVSS 8.8 (HIGH); EPSS percentile 31; sources: NVD.
- CVE-2026-40530 HIGH CVSS 8.0 -
NVD: An improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write arbitrary files and...
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary; CVSS 8.0 (HIGH); EPSS percentile 40; sources: NVD.
- CVE-2026-40539 HIGH CVSS 7.1 -
NVD: An improper certificate validation vulnerability in Email API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows man-in-the-middle attackers to read or write arbitrary files and conduct denial-of-service...
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 7.1 (HIGH); EPSS percentile 1; sources: NVD.
- CVE-2026-40535 MEDIUM CVSS 6.5 -
NVD: An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to write limited files and...
A remote attacker may be able to reach files outside the intended application path; CVSS 6.5 (MEDIUM); EPSS percentile 40; sources: NVD.
- CVE-2026-40532 MEDIUM CVSS 6.5 -
NVD: A direct request ('forced browsing') vulnerability in Wallpaper Path in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain sensitive information.
An attacker may be able to access information that should not be exposed; CVSS 6.5 (MEDIUM); EPSS percentile 34; sources: NVD.
- CVE-2026-21822 MEDIUM CVSS 6.3 -
NVD: HCLSoftware AppScan 360° was affected by a Path Traversal vulnerability in the ASReportService component. NVD: Improper handling of file paths allows an authenticated attacker to read or write files outside the intended directory, potentially enabling file system structure inspection or unauthorized file modification within the application's directory scope.
An attacker may be able to reach files outside the intended application path; CVSS 6.3 (MEDIUM); EPSS percentile 10; sources: NVD.
- CVE-2026-40534 MEDIUM CVSS 5.4 -
NVD: An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Video API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write...
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary; CVSS 5.4 (MEDIUM); EPSS percentile 17; sources: NVD.
- CVE-2026-40533 MEDIUM CVSS 5.3 -
NVD: An exposure of sensitive information through data queries vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to obtain non-sensitive information.
A remote attacker may be able to access information that should not be exposed; CVSS 5.3 (MEDIUM); EPSS percentile 29; sources: NVD.
- CVE-2026-13635 MEDIUM CVSS 5.3 -
NVD: An improper encoding or escaping of output vulnerability in Auth API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to obtain non-sensitive information.
A remote attacker may be able to access information that should not be exposed; CVSS 5.3 (MEDIUM); EPSS percentile 25; sources: NVD.
- CVE-2026-21848 MEDIUM CVSS 5.0 -
NVD: HCL BigFix Service Management is affected by a Security Misconfiguration vulnerability, which could allow an authenticated attacker to exploit improper access controls, enabling the unauthorized viewing of restricted data elements across tenant boundaries.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary; CVSS 5.0 (MEDIUM); EPSS percentile 5; sources: NVD.
- CVE-2026-13623 MEDIUM CVSS 4.8 -
NVD: An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Theme API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users with...
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary; CVSS 4.8 (MEDIUM); EPSS percentile 14; sources: NVD.
- CVE-2025-13533 MEDIUM CVSS 4.4 -
NVD: The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 12.0.6 via the Assignment Engine fields. NVD: This is due to insufficient input sanitization and output escaping on assignment data fields including Expressions, URLs, and Advanced assignment data. NVD: This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the CJT block edit screen in the admin dashboard.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary; CVSS 4.4 (MEDIUM); EPSS percentile 8; sources: NVD.
- CVE-2026-40531 MEDIUM CVSS 4.3 -
NVD: An integer overflow or wraparound vulnerability in File Operation in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to conduct limited denial-of-service attacks.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary; CVSS 4.3 (MEDIUM); EPSS percentile 35; sources: NVD.
- CVE-2026-40536 MEDIUM CVSS 4.3 -
NVD: An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive...
An attacker may be able to reach files outside the intended application path; CVSS 4.3 (MEDIUM); EPSS percentile 34; sources: NVD.
- CVE-2026-40537 MEDIUM CVSS 4.3 -
NVD: A server-side request forgery (SSRF) vulnerability in PersonMail API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information.
An attacker may be able to access information that should not be exposed; CVSS 4.3 (MEDIUM); EPSS percentile 23; sources: NVD.
- CVE-2026-40538 LOW CVSS 3.7 -
NVD: An improper restriction of excessive authentication attempts vulnerability in Auto block in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to read limited files via brute-force attacks.
This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure; CVSS 3.7 (LOW); EPSS percentile 28; sources: NVD.
- CVE-2026-13666 LOW CVSS 3.5 -
NVD: An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write limited files when...
This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary; CVSS 3.5 (LOW); EPSS percentile 14; sources: NVD.
- CVE-2026-13683 LOW CVSS 2.7 -
NVD: An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in EventScheduler API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated...
An attacker may be able to read or change database-backed application data; CVSS 2.7 (LOW); EPSS percentile 23; sources: NVD.