AI description
CVE-2026-13684 is identified as an improper encoding or escaping of output vulnerability found within the SCGI component of Synology DiskStation Manager (DSM). This flaw affects DSM versions prior to 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, and 7.4-90075. The vulnerability enables remote attackers to perform actions such as reading or writing arbitrary files and initiating denial-of-service attacks.
- Description
- An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.
- Source
- security@synology.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- security@synology.com
- CWE-116
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
10
๐จ SYNOLOGY DSM CRITICAL: UNAUTH ARBITRARY FILE R/W (CVSS 9.8) Synology published Synology-SA-26:13 for DiskStation Manager, rating the advisory Critical. Two unauthenticated remote vulnerabilities are scored CVSS 9.8: โข CVE-2026-13684 โ SCGI improper encoding/escaping; h
@DailyDarkWeb
19 Sept 2026
6327 Impressions
2 Retweets
18 Likes
9 Bookmarks
0 Replies
0 Quotes
๐๐จ SYNOLOGY DSM โ CVSS 9.8 ร2 CVE-2026-13639: Insufficient entropy โ session token prediction CVE-2026-13684: SCGI injection โ arbitrary file read/write โ https://t.co/6F99iDQezo #Synology #DSM #CVE #NAS #PatchNow #CyberSecurity #ThreatIntel
@ThreatAft
18 Sept 2026
45 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Synology fixed 8 DSM vulnerabilities, including two critical unauthenticated flaws (CVE-2026-13684, CVE-2026-13639) on DiskStation Manager. Update now. #Synology #DSM #NAS #CVE #Vulnerability #DiskStation #InfoSec #PatchNow #NetworkSecurity #DataStorage https://t.co/sQyw593efh
@Daily_CyberSec
18 Sept 2026
349 Impressions
0 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes