Skip to content
VulniPulse

Synology Security Advisories & CVEs

10 advisories tracked · Synology PSIRT (security@synology.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Synology CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your Synology device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Synology's recent advisories.

Official source

Synology PSIRT (security@synology.com CNA) via NVD

Synology is its own CVE Numbering Authority. VulniPulse ingests Synology's CVEs from the NVD CNA feed (security@synology.com), grouped by their official Synology_SA_YY_NN advisory, then enriches each from the advisory page — a fully server-rendered page carrying Synology's own severity rating, the affected-product / fixed-release table and the mitigation section. Covers DSM (DiskStation Manager), SRM (Router Manager), BeeStation, Synology Photos, Surveillance Station, Synology Drive and the SSL VPN Client.

Latest Synology advisories

Medium4.3Synology

Medium [CVE-2024-47273] Hyper Backup: improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functionality in…

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functionality in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users to write specific files via unspecified vectors.

CVE-2024-47273
Applications
Jun 3, 2026
Medium4.1Synology

Medium [CVE-2024-47263] Hyper Backup: improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository webapi…

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup. Repository webapi component in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users with administrator privileges to write specific files containing non-sensitive information via unspecified vectors.

CVE-2024-47263
Applications
Jun 3, 2026
Medium5.9Synology

Medium [CVE-2023-52951] cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703

A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle attackers to obtain user credential.

CVE-2023-52951
Unclassified
Jun 3, 2026
Medium6.2Synology

Medium [CVE-2026-2237] use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 allows local users on Windows to obtain sensitive information

A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 allows local users on Windows to obtain sensitive information. Affected products named by the advisory: Storage Manager for DSM 7.3; Storage Manager for DSM 7.2.2; Storage Manager for DSM 7.2.1.

CVE-2026-2237
DSM (DiskStation Manager)
May 27, 2026
Medium6.1Synology

Medium [CVE-2025-66593] origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation

An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.

CVE-2025-66593
Unclassified
May 27, 2026
Medium6.1Synology

Medium [CVE-2025-66592] origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation

An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.

CVE-2025-66592
Applications
May 27, 2026
Medium6.1Synology

Medium [CVE-2025-13593] Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation

Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.

CVE-2025-13593
Unclassified
May 27, 2026
Medium5.4Synology

Medium [CVE-2025-13167] Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functionality in Synology Contacts before 1.0.10-20659 allows remote authenticated users to read or write specific files containing non-sensitive information via unspecified vectors

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functionality in Synology Contacts before 1.0.10-20659 allows remote authenticated users to read or write specific files containing non-sensitive information via unspecified vectors. Affected products named by the advisory: Synology Contacts for DSM 7.3; Synology Contacts for DSM 7.2.2; Synology Contacts for DSM 7.2.1.

CVE-2025-13167
DSM (DiskStation Manager)
May 27, 2026
Medium5.9Synology

Medium [CVE-2025-10466] Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Safe Access in Synology Safe Access before 1.3.1-0329 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information or conduct limited denial-of-service in SRM

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Safe Access in Synology Safe Access before 1.3.1-0329 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information or conduct limited denial-of-service in SRM. Affected product named by the advisory: Safe Access for SRM 1.3.

CVE-2025-10466
SRM (Router Manager)
May 27, 2026
Medium4.9Synology

Medium [CVE-2024-47267 +5] Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Archiving Pull functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Archiving Pull functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors. Affected products named by the advisory: Surveillance Station for DSM 7.2; Surveillance Station for DSM 7.1; Surveillance Station for DSM 6.2.

CVE-2024-47267CVE-2024-47268CVE-2024-47269+3
DSM (DiskStation Manager)Applications
May 27, 2026

← All vendors