CVE-2026-13684: Critical severity Synology DiskStation Manager (DSM) vulnerability
Published Sep 18, 2026
·Updated
An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.
Affected Software
1 affected component
Synology DiskStation Manager (DSM)>7.2.1-69057-12<=7.2.2-72806-9
Event History
Sep 18, 2026
CVE Published
via MITRE·08:19 AM
Data Sourced
via MITRE·08:19 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The issue is remotely exploitable over the network and requires no privileges or user interaction, according to the supplied vector.
2
Which DSM releases contain a fixed version?
Fixed versions are DSM 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, and 7.4-90075. Releases before those specified builds are affected.
3
What could a successful attacker do?
A remote attacker could read or write arbitrary files and cause denial of service. The provided severity vector indicates high impacts to confidentiality, integrity, and availability.