OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-13684

CRITICAL · CVSS 9.8 EPSS 0.60%

Source: NVD + CISA KEV + EPSS · Published 2026-09-18 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

An improper encoding or escaping of output vulnerability in Synology DiskStation Manager affects multiple versions prior to 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, and 7.4-90075, allowing remote attackers to read or write arbitrary files and potentially launch denial-of-service attacks. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized access and service disruptions. This critical vulnerability poses a significant threat to the integrity and availability of systems running Synology DSM.

CVE
CVE-2026-13684
Severity
CRITICAL
CVSS
9.8
EPSS
0.60%

Original NVD Description

An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.