Two critical Synology NAS bugs let strangers write files

Published

Synology has patched a set of flaws in DiskStation Manager, the operating system on its network-attached storage boxes, and two of them are rated 9.8 out of 10. Both let a remote attacker read or write arbitrary files on the device and knock it offline, and neither requires a password first.

The fixes landed on 18 September in Synology-SA-26:13, which the vendor has already marked resolved. Peru's national digital security centre picked it up the following day in its integrated digital security alert, which is where it crossed our desk.

Two 9.8s, neither needing a login

Synology assigned the scores itself, as the CVE numbering authority for its own products. The two critical entries are:

A third, CVE-2026-13673 at CVSS 8.8, is an incorrect permission assignment in the LDAP API. That one does need a valid account, which is the only reason it scores lower; the impact Synology describes is the same.

What the advisory does not say

What it doesn't explain is how any of this works. The advisory carries no exploitation detail, no proof of concept, no attack chain and no credit to an outside finder. The second entry is the odd one: weak randomness in login logic producing arbitrary file access isn't a chain you can guess at from the flaw class alone, and Synology has not published one. Neither Synology nor the Peruvian bulletin reports any exploitation. Treat all three as patch-now items on severity and exposure, not on evidence of attacks.

Exposure is the real argument for hurrying. NAS boxes are the appliance most likely to be sitting on a home or small-office internet connection with remote access enabled and nobody watching it, and ransomware crews have been aiming at them for years. IntelFusions covered a Babuk-derived family built to hit Windows, VMware and NAS systems earlier this year, and the pattern of unauthenticated bypasses on management software has been a steady theme, as in the N-able N-central login bypass CISA flagged in August.

Update DSM to 7.2.1-69057-12 or later

The fixed builds are DSM 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075. Anything below the fixed build on your release line is affected. If you can't patch immediately, take the device off the public internet: close inbound access, disable remote-access features such as QuickConnect along with any port forwarding to the box, and reach it over a VPN instead. That doesn't fix the LDAP issue for anyone who already has an account, but it puts the two unauthenticated paths out of a stranger's reach.

The same Peruvian bulletin carried three further advisories, covering a WordPress theme-installation flaw, a privilege-escalation issue in Microsoft Fabric, and a SQL injection bug in HCL BigFix Service Management.

Storage appliances are where organizations keep the things they would most hate to lose, and they're administered less often than anything else on the network. A 9.8 that needs no credentials is worth an evening.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions