Critical 1 vendor · 2 advisories
CVE-2026-40541
CVE-2026-40541: critical-severity vulnerability covered by 2 tracked advisory records across Synology. Compare affected products, fixed versions and…
Android app · Google Play
Monitor future Synology CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Matching phone alertsOptional email delivery
Synology2 advisories
- Critical9.0Critical [CVE-2026-40541] improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write arbitrary files and conduct denial-of-service attacks in DSMAug 28, 2026
- Critical9.0Critical [CVE-2026-40541 +2] improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write arbitrary files and conduct denial-of-service attacks in DSMAug 28, 2026