Critical 1 vendor · 2 advisories
CVE-2026-9491
CVE-2026-9491: critical-severity vulnerability covered by 2 tracked advisory records across Synology. Compare affected products, fixed versions and remediation.
Android app · Google Play
Monitor future Synology CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Matching phone alertsOptional email delivery
Synology2 advisories
- Critical9.0Critical [CVE-2026-40541 +2] improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write arbitrary files and conduct denial-of-service attacks in DSMAug 28, 2026
- Medium4.3Medium [CVE-2026-9491] server-ide request forgery (SSRF) vulnerability in webhook in Synology Chat Server before 2.4.5-22148 allows remote authenticated users to obtain non-sensitive informationAug 28, 2026