Synology patches nine DSM flaws, one scoring 9.8
Synology's critical DSM update closes nine vulnerabilities, including two rated 9.8, across the 7.4, 7.3, 7.2.2 and 7.2.1 branches.

Synology has published a critical security update for DiskStation Manager, the operating system behind its NAS boxes, closing nine vulnerabilities across every supported branch. The two worst are rated 9.8 and neither needs a valid account to reach: CVE-2026-13684 is an improper encoding or escaping flaw in DSM's SCGI handling that allows a remote attacker to read or write arbitrary files, and CVE-2026-13639 is an insufficient entropy bug in the login logic that carries the same score.
The advisory is dated 18 September and covers CVE-2026-13684, CVE-2026-13639, CVE-2026-13635, CVE-2026-13673, CVE-2026-6205, CVE-2026-13666, CVE-2026-13623 and CVE-2026-13683 alongside the remaining entries in the batch. Three of them are reachable by any remote attacker, allowing arbitrary file reads and writes, denial-of-service and the disclosure of non-sensitive information. Three more need a logged-in user, with one able to write limited files when a victim clicks a sharing link, and two require an authenticated administrator.
Which DSM builds close the holes
The fixes are split by branch rather than issued as a single release. DSM 7.4 owners need 7.4-90075 or above, DSM 7.3 needs 7.3.2-86009-4 or above, DSM 7.2.2 needs 7.2.2-72806-9 or above, and the oldest supported line, DSM 7.2.1, needs 7.2.1-69057-12 or above. Synology lists no mitigation, which means there is no configuration change or workaround that removes the exposure: the only route out is the upgrade.
Smaller and older models are not automatically out of scope. The advisory's fixed releases are version-based, so a NAS that has never been switched to automatic updates will still be running the vulnerable code even though a fix exists for it.
A second DSM advisory was refreshed the same day
A second DSM advisory, Synology-SA-26:06, was updated a few minutes later on the same afternoon. Originally published in April and rated Important rather than Critical, it covers ten further CVEs, including CVE-2026-40530, a CRLF injection flaw rated 8.0, with fixed builds at 7.3.2-86009-2, 7.2.2-72806-7 and 7.2.1-69057-10 for the branches it affects. Owners running any of those branches should treat both advisories as one patching job and take the highest build number available.
Our opinion
A 9.8 in the login path is the score that should reorganise somebody's evening. A NAS is the least glamorous machine in the house and usually the only place a family's photos exist in one copy, and the practical difference between an 8.0 that needs an admin session and a 9.8 that needs nothing at all is whether a stranger on the internet can reach the filesystem before you get round to the update. What makes this drop worth reading rather than skimming is the shape of it: nine CVEs at once, spread across four supported branches, with the two worst sitting in output handling and login entropy rather than in anything optional. That pattern points at plumbing that has not kept pace with the feature list, and it is the same plumbing every DSM install shares. The honest caveat is that Synology's advisories describe what an attacker could do, not what anyone has done, so there is no evidence here of exploitation in the wild. That is a reason to patch on your own schedule, not a reason to wait for a headline.