# CERT-FR Warns of Synology DSM Vulnerabilities

Published: 2026-09-21 · Severity: routine · Sectors: technology, infrastructure
Canonical: https://vorant.io/reports/91b83215-9bc7-547a-8991-d32c610e6176/cert-fr-warns-of-synology-dsm-vulnerabilities

> Multiple vulnerabilities in Synology DSM allow remote code execution, denial of service, and data confidentiality breaches; patches available.

CERT-FR has issued an advisory (CERTFR-2026-AVI-1209) detailing multiple vulnerabilities discovered in Synology's DiskStation Manager (DSM) operating system, which powers Synology NAS devices. The flaws affect DSM versions 7.2.1 (prior to 7.2.1-69057-12), 7.2.2 (prior to 7.2.2-72806-9), 7.3 (prior to 7.3.2-86009-4), and 7.4.x (prior to 7.4-90075). Eight CVEs are referenced: CVE-2026-13623, CVE-2026-13635, CVE-2026-13639, CVE-2026-13666, CVE-2026-13673, CVE-2026-13683, CVE-2026-13684, and CVE-2026-6205.

The vulnerabilities collectively enable a range of impacts including remote arbitrary code execution, remote denial of service, data confidentiality breaches, data integrity compromise, security policy bypass, indirect remote code injection (XSS), and SQL injection. No specific exploitation-in-the-wild has been reported by CERT-FR; the advisory is a standard vulnerability disclosure sourced from Synology's own security bulletin (Synology_SA_26_13, published 18 September 2026).

Defenders operating Synology NAS devices should prioritize patching to the fixed DSM versions referenced above. Given the exposure of NAS devices to remote networks and the potential for remote code execution, organizations should verify DSM version compliance and apply Synology's official patches promptly, particularly for internet-facing storage systems.

## Mentioned in this report

- Vulnerabilities: CVE-2026-13623, CVE-2026-13635, CVE-2026-13639, CVE-2026-13666, CVE-2026-13673, CVE-2026-13683, CVE-2026-13684, CVE-2026-6205

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1209

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/91b83215-9bc7-547a-8991-d32c610e6176/cert-fr-warns-of-synology-dsm-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
