Multiple vulnerabilities in Synology Chat Server for DSM allow remote attackers to cause…
Multiple vulnerabilities in Synology Chat Server for DSM allow remote attackers to cause DoS, data confidentiality and integrity compromise via SSRF and XSS.
French CERT has disclosed multiple security vulnerabilities affecting Synology Chat Server versions prior to 2.4.5-22148 across DSM 7.2.1, 7.2.2, and 7.3. The vulnerabilities include server-side request forgery (SSRF) and cross-site scripting (XSS) flaws that enable various attack vectors.
An attacker exploiting these vulnerabilities could achieve remote denial of service, compromise data confidentiality, and undermine data integrity. The advisory identifies three CVEs: CVE-2026-40541, CVE-2026-9491, and CVE-2026-9548, though specific technical details for each vulnerability are not provided in the advisory.
Synology has released patches in Chat Server version 2.4.5-22148 to address these issues. Organizations running affected versions should prioritize upgrading to the patched release to mitigate exploitation risks.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0687
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free