Synology

    Dashboard / Vendors

    Products: 111
    Vulnerabilities: 355
    Known Exploited: 0
    41
    Critical Level Threats
    120
    High Level Threats
    187
    Medium Level Threats
    7
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-9548

    An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write restricted files and conduct limited denial-of-service attacks in DSM.

    Last Modified: Sep 01, 2026
    Published: Aug 28, 2026

    CVE-2026-9491

    A server-ide request forgery (SSRF) vulnerability in webhook in Synology Chat Server before 2.4.5-22148 allows remote authenticated users to obtain non-sensitive information.

    Last Modified: Sep 01, 2026
    Published: Aug 28, 2026

    CVE-2026-40541

    An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write arbitrary files and conduct denial-of-service attacks in DSM.

    Last Modified: Sep 01, 2026
    Published: Aug 28, 2026

    CVE-2026-4793

    Local Permissions Misconfiguration Enabling Arbitrary File Read/Write and Installation Denial in Synology Assistant

    Last Modified: Aug 19, 2026
    Published: Aug 03, 2026

    CVE-2024-47263

    Path Traversal in Synology Hyper Backup Allows Admin Write Access

    Last Modified: Jun 05, 2026
    Published: Jun 03, 2026
    Items Per Page