CVE-2026-40539: High severity Synology DiskStation Manager (DSM) vulnerability
An improper certificate validation vulnerability in Email API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows man-in-the-middle attackers to read or write arbitrary files and conduct denial-of-service attacks.
Affected Software
Event History
Frequently Asked Questions
Which DSM releases need to be updated?
DSM releases before 7.2.1-69057-10, 7.2.2-72806-7, and 7.3.2-86009-2 are affected. Update to the applicable listed build or a later release.
What does an attacker need to exploit this issue?
The attacker must be able to perform a man-in-the-middle attack against the Email API connection. The CVSS vector indicates no privileges are required, but exploitation has high attack complexity and requires user interaction.
What is the potential impact of a successful attack?
A successful man-in-the-middle attacker can read or write arbitrary files and cause denial of service. This can affect confidentiality, integrity, and availability.