Cyber & AI intelligence
Wasteland.
Briefs indexed2769
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-13684 2026-09-18

Synology DSM Hit by Critical SCGI Flaw: CVE-2026-13684 Allows Unauthenticated File Read/Write

"Synology has disclosed a critical (CVSS 9.8) output-encoding vulnerability in the SCGI component of DiskStation Manager that lets unauthenticated remote attackers read or write arbitrary files and trigger…"

Synology has disclosed a critical (CVSS 9.8) output-encoding vulnerability in the SCGI component of DiskStation Manager that lets unauthenticated remote attackers read or write arbitrary files and trigger denial-of-service conditions.

What Is It

CVE-2026-13684 is an improper encoding or escaping of output vulnerability (CWE-116) in SCGI within Synology DiskStation Manager (DSM). According to Synology's advisory, the flaw allows remote attackers to read or write arbitrary files on affected NAS appliances and to conduct denial-of-service attacks.

The CVSS 3.1 vector, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, scores 9.8 CRITICAL, with an exploitability subscore of 3.9 and impact subscore of 5.9. In plain terms: network-reachable, low complexity, no privileges, no user interaction, and full compromise of confidentiality, integrity, and availability.

Why It Matters

Arbitrary file write on a storage appliance is a direct path to data destruction and, depending on where an attacker can land a file, to further compromise of the device. Arbitrary file read exposes whatever the NAS holds. Add denial-of-service to the same primitive and a single unauthenticated request can hit all three legs of the CIA triad.

At the time of writing, CVE-2026-13684 does not appear in the CISA Known Exploited Vulnerabilities catalog, so no federal remediation deadline is currently associated with it. KEV listing lags real-world activity, however, and absence from the catalog is not evidence that the flaw is unexploited; readers should check the catalog directly for the current status. NAS appliances such as DSM are in many deployments reachable from the internet, which would raise the practical risk regardless of KEV status; administrators should confirm whether their own devices are externally exposed rather than assume they are not.

What's Vulnerable

Synology DiskStation Manager (DSM), in the following version branches:

Branch Affected below
7.4 7.4-90075
7.3.2 7.3.2-86009-4
7.2.2 7.2.2-72806-9
7.2.1 7.2.1-69057-12

Versions below 7.2.1 are listed with unknown status in the vendor-supplied data.

Patch Status

Fixed builds are available. Upgrade to DSM 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, or 7.4-90075 or later, matching your current branch. No workarounds or mitigations are listed in the supplied source material.

The record was published 2026-09-18 and remains in NVD vulnStatus Received, meaning NVD analysis is not yet complete; the CVSS score and affected-version data come from Synology as the CNA.

Sources