Skip to content
VulniPulse

Synology DSM (DiskStation Manager) Vulnerabilities & Security Advisories

6 advisories tracked · Synology PSIRT (security@synology.com CNA) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Synology advisory that VulniPulse classified as DSM (DiskStation Manager), with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 3 high, 3 medium.

Android app · Google Play

Monitor Synology CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Synology PSIRT (security@synology.com CNA) via NVD

Synology is its own CVE Numbering Authority. VulniPulse ingests Synology's CVEs from the NVD CNA feed (security@synology.com), grouped by their official Synology_SA_YY_NN advisory, then enriches each from the advisory page — a fully server-rendered page carrying Synology's own severity rating, the affected-product / fixed-release table and the mitigation section. Covers DSM (DiskStation Manager), SRM (Router Manager), BeeStation, Synology Photos, Surveillance Station, Synology Drive and the SSL VPN Client.

Latest Synology DSM (DiskStation Manager) advisories

High8.6Vendor: MediumSynology

High [CVE-2025-30028] Active Backup: vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files.

Multiple vulnerabilities allow remote authenticated users with administrator privileges to read/write/delete specific files. Affected product named by the advisory: Active Backup. Affected products named by the advisory: Active Backup for Business for DSM 7.2; Active Backup for Business for DSM 7.1; Active Backup for Business for DSM 6.2.

CVE-2025-30028
DSM (DiskStation Manager)Applications
May 27, 2026
High7.5Synology

High [CVE-2025-14713] C2 Identity Edge Server for DSM 7.3: Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307

An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote attackers to obtain user credentials from the edge server. Affected products named by the advisory: C2. Affected products named by the advisory: C2 Identity Edge Server for DSM 7.3; C2 Identity Edge Server for DSM 7.2.2; C2 Identity Edge Server for DSM 7.2.1; C2 Identity Edge Server for DSM 7.1.

CVE-2025-14713
DSM (DiskStation Manager)
May 27, 2026
High8.1Synology

High [CVE-2025-13392] DSM 7.3: Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before…

Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected) allows remote attackers to bypass authentication with prior knowledge of the distinguished name (DN). Affected products named by the advisory: DSM 7.3; DSM 7.2.2.

CVE-2025-13392
DSM (DiskStation Manager)
May 27, 2026

← All Synology advisories