
🚨 SYNOLOGY DSM CRITICAL: UNAUTH ARBITRARY FILE R/W (CVSS 9.8) Synology published Synology-SA-26:13 for DiskStation Manager, rating the advisory Critical. Two unauthenticated remote vulnerabilities are scored CVSS 9.8: • CVE-2026-13684 — SCGI improper encoding/escaping; arbitrary file read/write and DoS • CVE-2026-13639 — login insufficient entropy; arbitrary file read/write and DoS Additional Important issues allow authenticated arbitrary file read/write (CVE-2026-13673) and arbitrary write (CVE-2026-6205). Affected: DSM 7.4 / 7.3 / 7.2.2 / 7.2.1. Fixed builds listed in the advisory. No workaround — upgrade. Official advisory: https://www.synology.com/en-global/security/advisory/Synology_SA_26_13 #DDW #DarkWeb #Synology #DSM #CVE #CyberSecurity #ThreatIntelligence
