Synology Security Advisories & CVEs
10 advisories tracked · Synology PSIRT (security@synology.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Synology CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Check if your Synology device is affected
Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Synology's recent advisories.
Official source
Synology PSIRT (security@synology.com CNA) via NVD
Synology is its own CVE Numbering Authority. VulniPulse ingests Synology's CVEs from the NVD CNA feed (security@synology.com), grouped by their official Synology_SA_YY_NN advisory, then enriches each from the advisory page — a fully server-rendered page carrying Synology's own severity rating, the affected-product / fixed-release table and the mitigation section. Covers DSM (DiskStation Manager), SRM (Router Manager), BeeStation, Synology Photos, Surveillance Station, Synology Drive and the SSL VPN Client.
Latest Synology advisories
Medium [CVE-2024-47273] Hyper Backup: improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functionality in…
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functionality in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users to write specific files via unspecified vectors.
Medium [CVE-2024-47263] Hyper Backup: improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository webapi…
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup. Repository webapi component in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users with administrator privileges to write specific files containing non-sensitive information via unspecified vectors.
Medium [CVE-2023-52951] cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703
A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle attackers to obtain user credential.
Medium [CVE-2026-2237] use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 allows local users on Windows to obtain sensitive information
A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 allows local users on Windows to obtain sensitive information. Affected products named by the advisory: Storage Manager for DSM 7.3; Storage Manager for DSM 7.2.2; Storage Manager for DSM 7.2.1.
Medium [CVE-2025-66593] origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation
An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.
Medium [CVE-2025-66592] origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation
An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.
Medium [CVE-2025-13593] Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation
Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.
Medium [CVE-2025-13167] Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functionality in Synology Contacts before 1.0.10-20659 allows remote authenticated users to read or write specific files containing non-sensitive information via unspecified vectors
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functionality in Synology Contacts before 1.0.10-20659 allows remote authenticated users to read or write specific files containing non-sensitive information via unspecified vectors. Affected products named by the advisory: Synology Contacts for DSM 7.3; Synology Contacts for DSM 7.2.2; Synology Contacts for DSM 7.2.1.
Medium [CVE-2025-10466] Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Safe Access in Synology Safe Access before 1.3.1-0329 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information or conduct limited denial-of-service in SRM
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Safe Access in Synology Safe Access before 1.3.1-0329 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information or conduct limited denial-of-service in SRM. Affected product named by the advisory: Safe Access for SRM 1.3.
Medium [CVE-2024-47267 +5] Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Archiving Pull functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Archiving Pull functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors. Affected products named by the advisory: Surveillance Station for DSM 7.2; Surveillance Station for DSM 7.1; Surveillance Station for DSM 6.2.