CVE-2026-13684: Improper Output Encoding in Synology DSM SCGI Enables Unauthenticated File Read/Write
ID: 0936f4e2-1c10-5d09-846b-d910ad0b411a
STIX ID: report--0936f4e2-1c10-5d09-846b-d910ad0b411a
Feed Name: CosmicBytez Labs
Threat Score
Synology patched a critical, unauthenticated SCGI output-encoding vulnerability (CVE-2026-13684, CVSS 9.8) in DSM that can allow remote attackers to read or write arbitrary files and cause denial-of-service; multiple DSM versions have fixes and administrators are advised to update immediately, restrict management interfaces, and monitor for anomalous file access or malformed SCGI requests.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
