Synology Security Advisories & CVEs
8 advisories tracked · Synology PSIRT (security@synology.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Synology CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Check if your Synology device is affected
Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Synology's recent advisories.
Official source
Synology PSIRT (security@synology.com CNA) via NVD
Synology is its own CVE Numbering Authority. VulniPulse ingests Synology's CVEs from the NVD CNA feed (security@synology.com), grouped by their official Synology_SA_YY_NN advisory, then enriches each from the advisory page — a fully server-rendered page carrying Synology's own severity rating, the affected-product / fixed-release table and the mitigation section. Covers DSM (DiskStation Manager), SRM (Router Manager), BeeStation, Synology Photos, Surveillance Station, Synology Drive and the SSL VPN Client.
Latest Synology advisories
High [CVE-2026-4793] incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and conduct denial-of-service during installation
An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and conduct denial-of-service during installation.
High [CVE-2022-49042] inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup…
An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via unspecified vectors.
High [CVE-2022-49036] inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for…
An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified vectors.
High [CVE-2025-30028] vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files
A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files. Affected products named by the advisory: Active Backup for Business for DSM 7.2; Active Backup for Business for DSM 7.1; Active Backup for Business for DSM 6.2.
High [CVE-2025-14713] Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote attackers to obtain user credentials from the edge server
An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote attackers to obtain user credentials from the edge server. Affected products named by the advisory: C2. Affected products named by the advisory: C2 Identity Edge Server for DSM 7.3; C2 Identity Edge Server for DSM 7.2.2; C2 Identity Edge Server for DSM 7.2.1; C2 Identity Edge Server for DSM 7.1.
High [CVE-2025-13392] Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected) allows remote attackers to bypass authentication with prior knowledge of the distinguished name (DN)
Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected) allows remote attackers to bypass authentication with prior knowledge of the distinguished name (DN). Affected products named by the advisory: DSM 7.3; DSM 7.2.2.
High [CVE-2023-52945 +1] Uncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to execute arbitrary code via unspecified vectors
Uncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to execute arbitrary code via unspecified vectors.
High [CVE-2021-47960 +1] files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access files within the installation directory via a local HTTP server bound to the loopback interface
A files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access files within the installation directory via a local HTTP server bound to the loopback interface. By leveraging user interaction with a crafted web page, attackers may retrieve sensitive files such as configuration files, certificates, and logs, leading to information disclosure.