Synology Applications Vulnerabilities & Security Advisories
3 advisories tracked · Synology PSIRT (security@synology.com CNA) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Synology advisory that VulniPulse classified as Applications, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 1 high, 2 medium.
Android app · Google Play
Monitor Synology CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Synology PSIRT (security@synology.com CNA) via NVD
Synology is its own CVE Numbering Authority. VulniPulse ingests Synology's CVEs from the NVD CNA feed (security@synology.com), grouped by their official Synology_SA_YY_NN advisory, then enriches each from the advisory page — a fully server-rendered page carrying Synology's own severity rating, the affected-product / fixed-release table and the mitigation section. Covers DSM (DiskStation Manager), SRM (Router Manager), BeeStation, Synology Photos, Surveillance Station, Synology Drive and the SSL VPN Client.
Latest Synology Applications advisories
High [CVE-2025-30028] Active Backup: vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files.
Multiple vulnerabilities allow remote authenticated users with administrator privileges to read/write/delete specific files. Affected product named by the advisory: Active Backup. Affected products named by the advisory: Active Backup for Business for DSM 7.2; Active Backup for Business for DSM 7.1; Active Backup for Business for DSM 6.2.
Medium [CVE-2025-66592] Synology Active Backup for Business Agent: Synology has released a security update for the Active Backup for Business Agent on Windows to address a vulnerability…
Synology has released a security update for the Active Backup for Business Agent on Windows to address a vulnerability: CVE-2025-66592 allows local users to write arbitrary files with restricted content. Please refer to the ' Affected product named by the advisory: Synology Active Backup for Business Agent.
Medium [CVE-2024-47267 +5] Surveillance Station for DSM 7.2: Multiple vulnerabilities allow remote authenticated users to inject arbitrary web script or HTML
Multiple vulnerabilities allow remote authenticated users to inject arbitrary web script or HTML. Multiple vulnerabilities allow remote authenticated users to obtain sensitive information. Multiple vulnerabilities allow remote authenticated users with administrator privileges to read or write specific files. Affected product named by the advisory: Surveillance Station. Affected products named by the advisory: Surveillance Station for DSM 7.2; Surveillance Station for DSM 7.1; Surveillance Station for DSM 6.2.