PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-40535 Synology CVE debrief

CVE-2026-40535 is a path traversal vulnerability in Synology DiskStation Manager (DSM) that allows remote attackers to write limited files and conduct limited denial-of-service attacks. The vulnerability affects DSM versions before 7.2.1-69057-10, 7.2.2-72806-7, and 7.3.2-86009-2. Defenders should assess exposure and prioritize patching for affected versions, verifying DSM versions and configurations for potential exploitation. This vulnerability has a medium severity rating and a CVSS score of 6.5.

Vendor
Synology
Product
DiskStation Manager (DSM)
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-18
Original CVE updated
2026-09-18
Advisory published
2026-09-18
Advisory updated
2026-09-18

Who should care

Defenders responsible for Synology DiskStation Manager (DSM) deployments should assess exposure and prioritize patching for affected versions. This includes verifying DSM versions and configurations for potential exploitation, monitoring for potential denial-of-service attacks, and reviewing compensating controls for exposed systems.

Why it matters

CVE-2026-40535 is a medium-severity path traversal vulnerability in Synology DiskStation Manager (DSM) that allows remote attackers to write limited files and conduct limited denial-of-service attacks. Defenders responsible for DSM deployments should assess exposure and prioritize patching for affected versions.

  • Remote attackers can write limited files
  • Remote attackers can conduct limited denial-of-service attacks
  • Defenders need to verify DSM versions and configurations for exposure
  • Patching is required to prevent exploitation

Technical summary

The CVE-2026-40535 vulnerability is an improper limitation of a pathname to a restricted directory ('path traversal') in the Desktop API of Synology DiskStation Manager (DSM). This allows remote attackers to write limited files and conduct limited denial-of-service attacks. The vulnerability affects DSM versions before 7.2.1-69057-10, 7.2.2-72806-7, and 7.3.2-86009-2. Defenders should assess exposure and prioritize patching for affected versions, verifying DSM versions and configurations for potential exploitation.

Defensive priority

Medium-priority patching and verification recommended

Recommended defensive actions

  • Apply patches from Synology for affected DSM versions
  • Verify DSM versions and configurations for exposure
  • Monitor for potential denial-of-service attacks
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability, with a CVSS score of 6.5 and a MEDIUM severity rating. The CVE record was published on 2026-09-18T09:16:40.960Z and has not been modified since then. Synology security advisories and official documentation should be reviewed for detailed guidance on affected versions and patching instructions. Defenders need to verify DSM versions and configurations for exposure and prioritize patching for affected versions.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-40535 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-40535

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-40535 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-40535

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.