PatchSiren cyber security CVE debrief
CVE-2026-40535 Synology CVE debrief
CVE-2026-40535 is a path traversal vulnerability in Synology DiskStation Manager (DSM) that allows remote attackers to write limited files and conduct limited denial-of-service attacks. The vulnerability affects DSM versions before 7.2.1-69057-10, 7.2.2-72806-7, and 7.3.2-86009-2. Defenders should assess exposure and prioritize patching for affected versions, verifying DSM versions and configurations for potential exploitation. This vulnerability has a medium severity rating and a CVSS score of 6.5.
- Vendor
- Synology
- Product
- DiskStation Manager (DSM)
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-18
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-09-18
- Advisory updated
- 2026-09-18
Who should care
Defenders responsible for Synology DiskStation Manager (DSM) deployments should assess exposure and prioritize patching for affected versions. This includes verifying DSM versions and configurations for potential exploitation, monitoring for potential denial-of-service attacks, and reviewing compensating controls for exposed systems.
Why it matters
CVE-2026-40535 is a medium-severity path traversal vulnerability in Synology DiskStation Manager (DSM) that allows remote attackers to write limited files and conduct limited denial-of-service attacks. Defenders responsible for DSM deployments should assess exposure and prioritize patching for affected versions.
- Remote attackers can write limited files
- Remote attackers can conduct limited denial-of-service attacks
- Defenders need to verify DSM versions and configurations for exposure
- Patching is required to prevent exploitation
Technical summary
The CVE-2026-40535 vulnerability is an improper limitation of a pathname to a restricted directory ('path traversal') in the Desktop API of Synology DiskStation Manager (DSM). This allows remote attackers to write limited files and conduct limited denial-of-service attacks. The vulnerability affects DSM versions before 7.2.1-69057-10, 7.2.2-72806-7, and 7.3.2-86009-2. Defenders should assess exposure and prioritize patching for affected versions, verifying DSM versions and configurations for potential exploitation.
Defensive priority
Medium-priority patching and verification recommended
Recommended defensive actions
- Apply patches from Synology for affected DSM versions
- Verify DSM versions and configurations for exposure
- Monitor for potential denial-of-service attacks
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability, with a CVSS score of 6.5 and a MEDIUM severity rating. The CVE record was published on 2026-09-18T09:16:40.960Z and has not been modified since then. Synology security advisories and official documentation should be reviewed for detailed guidance on affected versions and patching instructions. Defenders need to verify DSM versions and configurations for exposure and prioritize patching for affected versions.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-40535 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-40535
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-40535 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-40535
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.synology.com/en-global/security/advisory/Synology_SA_26_06
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.