Multiple vulnerabilities in Synology DSM (September 21, 2026)
Reporting by CERT-FR AdvisoriesRead the original at cert.ssi.gouv.fr
Executive Summary
Facts Only
* Vulnerabilities discovered in Synology DSM were identified.
* Risks include compromise of data integrity and confidentiality.
* Exploitable risks involve remote denial of service and remote arbitrary code execution.
* Other specific risks listed are remote code injection (XSS) and SQL Injection (SQLi).
* Affected systems include DSM versions prior to 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, and 7.4.x prior to 7.4-90075.
* Solutions require referencing the vendor's security bulletin for patches.
* Specific CVE references include CVE-2026-13623 through CVE-2026-6205.
Full Take
From the original · CERT-FR Advisories
Risks - Compromise of data integrity - Compromise of data confidentiality - Circumvention of security policy - Remote denial of service - Remote arbitrary code execution - Remote code injection (XSS) - SQL Injection (SQLi) - Not specified by the vendor Affected Systems - DSM versions prior to 7.2.1-69057-12 - DSM versions prior to 7.2.2-72806-9 - DSM versions prior to 7.3.2-86009-4 - DSM versions…Read the full story at cert.ssi.gouv.fr
Sentinel — Human
This text appears to be a direct extraction or summary of a formal security advisory. It lacks the rhetorical flourishes typical of synthesized editorial content and relies heavily on specific, verifiable technical references.
