Complete feed
Security advisories & CVEs
22 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Critical [CVE-2026-40541 +2] improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write arbitrary files and conduct denial-of-service attacks in DSM
Synology has released a security update for the Synology Chat Server package in DSM to address multiple vulnerabilities: CVE-2026-40541 allows remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks. CVE-2026-9491 allows remote authenticated users to obtain non-sensitive information. Please refer to the ' Affected products named by the advisory: Synology Chat Server for DSM 7.3; Synology Chat Server for DSM 7.2.2; Synology Chat Server for DSM 7.2.1.
Medium [CVE-2026-9548] improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write restricted files and conduct limited denial-of-service attacks in DSM
Synology has released a security update for the Synology Chat Server package in DSM to address multiple vulnerabilities: CVE-2026-40541 allows remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks. CVE-2026-9491 allows remote authenticated users to obtain non-sensitive information. Please refer to the ' Affected products named by the advisory: Synology Chat Server for DSM 7.3; Synology Chat Server for DSM 7.2.2; Synology Chat Server for DSM 7.2.1.
Medium [CVE-2026-9491] server-ide request forgery (SSRF) vulnerability in webhook in Synology Chat Server before 2.4.5-22148 allows remote authenticated users to obtain non-sensitive information
Synology has released a security update for the Synology Chat Server package in DSM to address multiple vulnerabilities: CVE-2026-40541 allows remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks. CVE-2026-9491 allows remote authenticated users to obtain non-sensitive information. Please refer to the ' Affected products named by the advisory: Synology Chat Server for DSM 7.3; Synology Chat Server for DSM 7.2.2; Synology Chat Server for DSM 7.2.1.
High [CVE-2026-4793] incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and conduct denial-of-service during installation
An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and conduct denial-of-service during installation.
High [CVE-2022-49042] inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup…
An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via unspecified vectors.
High [CVE-2022-49036] inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for…
An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified vectors.
Medium [CVE-2024-47273] Hyper Backup: improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functionality in…
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functionality in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users to write specific files via unspecified vectors.
Medium [CVE-2024-47263] Hyper Backup: improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository webapi…
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup. Repository webapi component in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users with administrator privileges to write specific files containing non-sensitive information via unspecified vectors.
Medium [CVE-2023-52951] cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703
A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle attackers to obtain user credential.
Critical [CVE-2025-12686] Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStation OS before 1.3.2-65648 allows remote attackers to execute arbitrary code via unspecified vectors
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStation OS before 1.3.2-65648 allows remote attackers to execute arbitrary code via unspecified vectors. Affected products named by the advisory: BeeStation OS 1.3; BeeStation OS 1.2; BeeStation OS 1.1; BeeStation OS 1.0.
High [CVE-2025-30028] vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files
A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files. Affected products named by the advisory: Active Backup for Business for DSM 7.2; Active Backup for Business for DSM 7.1; Active Backup for Business for DSM 6.2.
High [CVE-2025-14713] Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote attackers to obtain user credentials from the edge server
An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote attackers to obtain user credentials from the edge server. Affected products named by the advisory: C2. Affected products named by the advisory: C2 Identity Edge Server for DSM 7.3; C2 Identity Edge Server for DSM 7.2.2; C2 Identity Edge Server for DSM 7.2.1; C2 Identity Edge Server for DSM 7.1.
High [CVE-2025-13392] Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected) allows remote attackers to bypass authentication with prior knowledge of the distinguished name (DN)
Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected) allows remote attackers to bypass authentication with prior knowledge of the distinguished name (DN). Affected products named by the advisory: DSM 7.3; DSM 7.2.2.
High [CVE-2023-52945 +1] Uncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to execute arbitrary code via unspecified vectors
Uncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to execute arbitrary code via unspecified vectors.
Medium [CVE-2026-2237] use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 allows local users on Windows to obtain sensitive information
A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 allows local users on Windows to obtain sensitive information. Affected products named by the advisory: Storage Manager for DSM 7.3; Storage Manager for DSM 7.2.2; Storage Manager for DSM 7.2.1.
Medium [CVE-2025-66593] origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation
An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.
Medium [CVE-2025-66592] origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation
An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.
Medium [CVE-2025-13593] Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation
Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.
Medium [CVE-2025-13167] Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functionality in Synology Contacts before 1.0.10-20659 allows remote authenticated users to read or write specific files containing non-sensitive information via unspecified vectors
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functionality in Synology Contacts before 1.0.10-20659 allows remote authenticated users to read or write specific files containing non-sensitive information via unspecified vectors. Affected products named by the advisory: Synology Contacts for DSM 7.3; Synology Contacts for DSM 7.2.2; Synology Contacts for DSM 7.2.1.
Medium [CVE-2025-10466] Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Safe Access in Synology Safe Access before 1.3.1-0329 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information or conduct limited denial-of-service in SRM
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Safe Access in Synology Safe Access before 1.3.1-0329 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information or conduct limited denial-of-service in SRM. Affected product named by the advisory: Safe Access for SRM 1.3.