CVE-2026-40539
- EPSS 0.08%
- Veröffentlicht 18.09.2026 08:29:33
- Zuletzt bearbeitet 18.09.2026 19:07:38
An improper certificate validation vulnerability in Email API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows man-in-the-middle attackers to read or write arbitrary files and conduct denial-of-servi...
CVE-2026-40538
- EPSS 0.25%
- Veröffentlicht 18.09.2026 08:29:15
- Zuletzt bearbeitet 18.09.2026 19:07:38
An improper restriction of excessive authentication attempts vulnerability in Auto block in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to read limited files via brute-force attack...
CVE-2026-40535
- EPSS 0.43%
- Veröffentlicht 18.09.2026 08:28:55
- Zuletzt bearbeitet 18.09.2026 19:07:38
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to write limited files...
CVE-2026-40533
- EPSS 0.29%
- Veröffentlicht 18.09.2026 08:28:35
- Zuletzt bearbeitet 18.09.2026 19:07:38
An exposure of sensitive information through data queries vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to obtain non-sensitive information.
CVE-2026-40537
- EPSS 0.25%
- Veröffentlicht 18.09.2026 08:28:13
- Zuletzt bearbeitet 18.09.2026 19:07:38
A server-side request forgery (SSRF) vulnerability in PersonMail API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information.
CVE-2026-40536
- EPSS 0.37%
- Veröffentlicht 18.09.2026 08:27:53
- Zuletzt bearbeitet 18.09.2026 19:07:38
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-...
CVE-2026-40534
- EPSS 0.2%
- Veröffentlicht 18.09.2026 08:27:28
- Zuletzt bearbeitet 18.09.2026 19:07:38
An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Video API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read ...
CVE-2026-40532
- EPSS 0.32%
- Veröffentlicht 18.09.2026 08:27:07
- Zuletzt bearbeitet 18.09.2026 20:17:15
A direct request ('forced browsing') vulnerability in Wallpaper Path in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain sensitive information.
CVE-2026-40531
- EPSS 0.33%
- Veröffentlicht 18.09.2026 08:26:45
- Zuletzt bearbeitet 18.09.2026 20:17:15
An integer overflow or wraparound vulnerability in File Operation in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to conduct limited denial-of-service attacks.
CVE-2026-4036
- EPSS 0.34%
- Veröffentlicht 18.09.2026 08:26:18
- Zuletzt bearbeitet 18.09.2026 20:17:16
An improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obt...