Skip to content
VulniPulse

Synology DSM (DiskStation Manager) Vulnerabilities & Security Advisories

6 advisories tracked · Synology PSIRT (security@synology.com CNA) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Synology advisory that VulniPulse classified as DSM (DiskStation Manager), with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 3 high, 3 medium.

Android app · Google Play

Monitor Synology CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Synology PSIRT (security@synology.com CNA) via NVD

Synology is its own CVE Numbering Authority. VulniPulse ingests Synology's CVEs from the NVD CNA feed (security@synology.com), grouped by their official Synology_SA_YY_NN advisory, then enriches each from the advisory page — a fully server-rendered page carrying Synology's own severity rating, the affected-product / fixed-release table and the mitigation section. Covers DSM (DiskStation Manager), SRM (Router Manager), BeeStation, Synology Photos, Surveillance Station, Synology Drive and the SSL VPN Client.

Latest Synology DSM (DiskStation Manager) advisories

Medium6.2Synology

Medium [CVE-2026-2237] Storage Manager for DSM 7.3: use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package…

A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 allows local users on Windows to obtain sensitive information. Affected products named by the advisory: Storage Manager for DSM 7.3; Storage Manager for DSM 7.2.2; Storage Manager for DSM 7.2.1.

CVE-2026-2237
DSM (DiskStation Manager)
May 27, 2026
Medium5.4Synology

Medium [CVE-2025-13167] Synology Contacts for DSM 7.3: Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functionality in…

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functionality in Synology Contacts before 1.0.10-20659 allows remote authenticated users to read or write specific files containing non-sensitive information via unspecified vectors. Affected products named by the advisory: Synology Contacts for DSM 7.3; Synology Contacts for DSM 7.2.2; Synology Contacts for DSM 7.2.1.

CVE-2025-13167
DSM (DiskStation Manager)
May 27, 2026
Medium4.9Synology

Medium [CVE-2024-47267 +5] Surveillance Station for DSM 7.2: Multiple vulnerabilities allow remote authenticated users to inject arbitrary web script or HTML

Multiple vulnerabilities allow remote authenticated users to inject arbitrary web script or HTML. Multiple vulnerabilities allow remote authenticated users to obtain sensitive information. Multiple vulnerabilities allow remote authenticated users with administrator privileges to read or write specific files. Affected product named by the advisory: Surveillance Station. Affected products named by the advisory: Surveillance Station for DSM 7.2; Surveillance Station for DSM 7.1; Surveillance Station for DSM 6.2.

CVE-2024-47267CVE-2024-47268CVE-2024-47269+3
DSM (DiskStation Manager)Applications
May 27, 2026

← All Synology advisories