logo

CVE-2026-13639: Insufficient Entropy in Synology DSM Login Lets Unauthenticated Attackers Read/Write Files

ID: 5b21dff7-0ce3-5d70-ad7c-624cb64bbbb8

STIX ID: report--5b21dff7-0ce3-5d70-ad7c-624cb64bbbb8

Feed Name: CosmicBytez Labs

Threat Score
88/100

Date Published: 2026-09-19

Date Updated: 2026-09-19

...
...

**Synology DSM critical vulnerability (CVE-2026-13639, CVSS 9.8)**: a login‑logic insufficient-entropy flaw enables unauthenticated remote attackers to read/write arbitrary files and cause denial-of-service on affected DSM versions (prior to 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, 7.4-90075). The advisory groups this with two other issues (CVE-2026-13684, CVE-2026-13635); Synology provides fixes only via updated DSM builds and recommends immediate patching, removing internet exposure of management interfaces, and auditing logs for suspicious activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.