CVE-2026-40531: Integer Overflow
Published Sep 18, 2026
·Updated
An integer overflow or wraparound vulnerability in File Operation in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to conduct limited denial-of-service attacks.
Affected Software
1 affected component
Synology DiskStation Manager (DSM)<7.2.1-69057-10, <7.2.2-72806-7, <7.3.2-86009-2
Event History
Sep 18, 2026
CVE Published
via MITRE·08:26 AM
Data Sourced
via MITRE·08:26 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A remote attacker must be authenticated to DSM. The available information does not indicate that unauthenticated users can exploit it.
2
What is the practical impact of a successful attack?
A successful exploit can cause a limited denial of service. No confidentiality or integrity impact is stated.
3
Which DSM releases contain fixes?
Fixed versions are DSM 7.2.1-69057-10, 7.2.2-72806-7, and 7.3.2-86009-2. Systems running earlier versions in those release lines are affected.