OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-13639

CRITICAL · CVSS 9.8 EPSS 0.66%

Source: NVD + CISA KEV + EPSS · Published 2026-09-18 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

An insufficient entropy vulnerability in the login logic of Synology DiskStation Manager prior to specified versions allows remote attackers to exploit the system, potentially leading to unauthorized file access and denial-of-service attacks. Organizations using affected versions of DSM should prioritize patching to mitigate the risk of data breaches and service disruptions. This is particularly critical for businesses relying on Synology devices for data storage and management.

CVE
CVE-2026-13639
Severity
CRITICAL
CVSS
9.8
EPSS
0.66%

Original NVD Description

An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.