CVE-2026-13639: Insufficient Entropy in Synology DSM Login Lets Unauthenticated Attackers Read/Write Files
ID: 5b21dff7-0ce3-5d70-ad7c-624cb64bbbb8
STIX ID: report--5b21dff7-0ce3-5d70-ad7c-624cb64bbbb8
Feed Name: CosmicBytez Labs
**Synology DSM critical vulnerability (CVE-2026-13639, CVSS 9.8)**: a login‑logic insufficient-entropy flaw enables unauthenticated remote attackers to read/write arbitrary files and cause denial-of-service on affected DSM versions (prior to 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, 7.4-90075). The advisory groups this with two other issues (CVE-2026-13684, CVE-2026-13635); Synology provides fixes only via updated DSM builds and recommends immediate patching, removing internet exposure of management interfaces, and auditing logs for suspicious activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
