logo

CVE-2026-13684: Improper Output Encoding in Synology DSM SCGI Enables Unauthenticated File Read/Write

ID: 0936f4e2-1c10-5d09-846b-d910ad0b411a

STIX ID: report--0936f4e2-1c10-5d09-846b-d910ad0b411a

Feed Name: CosmicBytez Labs

Threat Score
80/100

Date Published: 2026-09-19

Date Updated: 2026-09-19

...
...

Synology patched a critical, unauthenticated SCGI output-encoding vulnerability (CVE-2026-13684, CVSS 9.8) in DSM that can allow remote attackers to read or write arbitrary files and cause denial-of-service; multiple DSM versions have fixes and administrators are advised to update immediately, restrict management interfaces, and monitor for anomalous file access or malformed SCGI requests.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.