9/18/2026 • Security
Synology Fixes Two Critical NAS Flaws No Login Could Stop
Synology's SA-26:13 patches eight DSM vulnerabilities, including two unauthenticated CVSS 9.8 bugs that let remote attackers read or write arbitrary files on a NAS with no credentials at all. Here's what's confirmed, and what to do about it.
Synology shipped a single advisory this week fixing eight vulnerabilities in DSM, the operating system behind its DiskStation NAS boxes — and two of them, rated a maximum-adjacent 9.8 out of 10, don't need a password to use. An attacker who can reach the management interface can read or write arbitrary files on the device, no login required.
What happened, in plain English
On 18 September 2026, Synology published advisory SA-26:13, covering eight CVEs across DSM 7.2.1 through 7.4:
- CVE-2026-13684 — an encoding flaw in DSM's SCGI component (CWE-116). CVSS 9.8, vector
AV:N/AC:L/PR:N/UI:N: reachable over the network, no privileges, no user interaction. It allows remote attackers to read or write arbitrary files and trigger denial-of-service. - CVE-2026-13639 — an insufficient-entropy flaw in DSM's login logic (CWE-331). Also CVSS 9.8, same unauthenticated, no-interaction profile, same read/write/DoS impact.
Those two are genuinely unauthenticated — worth stating plainly, because that word gets stretched a lot in security news and here it's accurate. The other six require some level of access first:
- CVE-2026-13673 (CVSS 8.8) — a permissions flaw in the LDAP API lets an already-authenticated user read or write arbitrary files and cause DoS.
- CVE-2026-6205 (CVSS 8.1) — a path-handling flaw in the Upload API lets an authenticated user write arbitrary files.
- CVE-2026-13635 (CVSS 5.3) — an Auth API encoding issue that leaks non-sensitive information, no login needed.
- CVE-2026-13623 (CVSS 4.8) — a Theme API cross-site scripting flaw, but it needs an administrator account and a user to interact with a crafted page.
- CVE-2026-13666 (CVSS 3.5) — a CRLF injection in the Sharing API that can write limited files, but only if a signed-in user clicks a malicious sharing link.
- CVE-2026-13683 (CVSS 2.7) — a SQL injection in EventScheduler, again gated behind an administrator account.
All eight affect DSM 7.2.1, 7.2.2, 7.3 and 7.4. Synology's fix is a straight upgrade, with no interim workaround offered:
| DSM version | Fixed build |
|---|---|
| 7.4 | 7.4-90075 or later |
| 7.3 | 7.3.2-86009-4 or later |
| 7.2.2 | 7.2.2-72806-9 or later |
| 7.2.1 | 7.2.1-69057-12 or later |
One nuance worth being upfront about: as of publication, there's no evidence these are being actively exploited. They're not on CISA's Known Exploited Vulnerabilities catalogue, and no public proof-of-concept has surfaced. A 9.8 with no attacker interest yet is still a 9.8 — the score describes what the bug can do, not whether someone's doing it. The safe reading is "patch before that changes," not "panic because it already has."
Why a NAS bug like this matters more than most
Most of what we cover in this series is edge equipment — routers, firewalls, VPN gateways — where the risk is a foothold into your network. A NAS is a different kind of target: it's not passing your traffic, it's holding your stuff. Invoices, contracts, backups, customer records, sometimes the only copy of any of it. An arbitrary file read/write bug on a device like that isn't "an attacker could get in" — for the two unauthenticated flaws, it's "an attacker could get your files, without needing to get in at all."
It's also worth remembering how these boxes actually get used in a small business. DSM is commonly reachable from outside the LAN — QuickConnect, reverse-proxied web access, or a straight port-forward to 5000/5001 — because remote access to shared files is the whole point of owning one. That's convenient, but it also means the "remote attacker, no credentials" column in a CVSS vector isn't a lab scenario for a lot of these boxes; it's the box's normal operating mode.
The honest bit
No vendor is immune, including the ones we're happy to sell. Synology has had critical flaws before — including ones demonstrated live at Pwn2Own — and this advisory bundles two more critical, unauthenticated bugs. What we'd flag in their favour: this is a single coordinated advisory covering all eight issues at once, with credit given to the external researchers who reported them, clean CVE records, and fixed builds already published for every affected branch. That's what a healthy disclosure-to-patch pipeline looks like, whoever the vendor is — we've made this same point before, with Cisco's own RV routers and with Fortinet's credential-exposure bug, because it's the standard we hold every vendor to, not just the ones we don't sell.
One genuine, non-salesy point in DSM's favour: it supports scheduled and automatic updates, so "patch this" doesn't have to mean someone remembering to log in and click a button. If you haven't turned that on, this is a good week to.
What we'd suggest you actually do
- Find every Synology NAS your business runs, including ones in a back office or server room nobody thinks about day to day, and check its DSM version (Control Panel → Update & Restore).
- Upgrade to the fixed build for your branch — 7.4-90075, 7.3.2-86009-4, 7.2.2-72806-9 or 7.2.1-69057-12, whichever applies. There's no workaround short of patching.
- Turn on automatic DSM updates, at least for security patches, so the next one doesn't wait on anyone's to-do list.
- Check what's actually exposed to the internet. If DSM's admin interface is directly port-forwarded rather than accessed through a VPN or a properly configured reverse proxy, that's worth fixing independently of this advisory.
- Tidy up accounts. Several of these flaws only need a low-privileged, already-authenticated user to do damage — so keep local DSM accounts to people who need them, enable two-factor authentication, and remove anything stale or shared.
The friendly takeaway
Two of these eight bugs are as serious as this series sees: unauthenticated, remote, file read/write, on a device built to hold your business's data. Nobody's reported them being used in the wild yet, and Synology has already shipped the fix — which means the outcome here is entirely in the "did you patch it" column. If you'd like a second pair of eyes on what's exposed on your network, NAS included, get in touch — no obligation, no hard sell.
References
- Synology Security Advisory SA-26:13
- NVD — CVE-2026-13684 (CVSS 9.8)
- NVD — CVE-2026-13639 (CVSS 9.8)
- NVD — CVE-2026-13673 (CVSS 8.8)
- NVD — CVE-2026-6205 (CVSS 8.1)
- NVD — CVE-2026-13635 (CVSS 5.3)
- NVD — CVE-2026-13623 (CVSS 4.8)
- NVD — CVE-2026-13666 (CVSS 3.5)
- NVD — CVE-2026-13683 (CVSS 2.7)
- CISA Known Exploited Vulnerabilities Catalog