Important2026-04-15

Synology-SA-26:06 DSM security update

Synology published a broad DSM security advisory covering 11 vulnerabilities, with explicit fixed releases across current supported DSM branches.

AffectedDSM 7.3, DSM 7.2.2, DSM 7.2.1
Fixed version(s)DSM 7.3.2-86009-2+, DSM 7.2.2-72806-7+, DSM 7.2.1-69057-10+
Moderate2026-03-31

Synology-SA-26:04 Mail Station security update

Synology published a Mail Station package advisory for DSM after disclosing that CVE-2026-5129 may allow remote authenticated users to read or write limited files.

AffectedMail Station for DSM 7.3, Mail Station for DSM 7.2.2, Mail Station for DSM 7.2.1
Fixed version(s)Mail Station 30000001.3.19-20332+ for DSM 7.3 and 7.2.x
Critical2026-03-19

Synology-SA-26:03 DSM critical security update

Synology disclosed a critical DSM update for GNU Inetutils telnetd after warning that CVE-2026-32746 may allow unauthenticated remote attackers to execute arbitrary commands.

AffectedDSM 7.3, DSM 7.2.2, DSM 7.2.1, DSMUC 3.1
Fixed version(s)DSM 7.3.2-86009-3+, DSM 7.2.2-72806-8+, DSM 7.2.1-69057-11+
Moderate2026-02-09

Synology-SA-26:01 Storage Manager

Synology released a Storage Manager package security update for DSM 7.3 and DSM 7.2.x after disclosing a local information exposure issue.

AffectedStorage Manager for DSM 7.3, Storage Manager for DSM 7.2.2, Storage Manager for DSM 7.2.1
Fixed version(s)1.0.1-1100 or above
Moderate2025-09-16

Synology-SA-25:11 Safe Access

Safe Access for SRM 1.3 received a security update for a vulnerability that could allow remote authenticated administrator-level users to read or write limited files.

AffectedSafe Access for SRM 1.3
Fixed version(s)1.3.1-0329 or above
Moderate2025-08-29

Synology-SA-25:10 RADIUS Server

RADIUS Server for SRM 1.3 received a fix for an XSS issue that could let remote authenticated administrator-level users read or write limited files and conduct limited DoS.

AffectedRADIUS Server for SRM 1.3
Fixed version(s)3.0.27-0139 or above
Moderate2025-05-29

Synology-SA-25:07 SMB Service

Synology disclosed an SMB Service issue where remote authenticated users could write to limited files; DSM packages received fixed builds and SRM/BeeStation remained ongoing at publication time.

AffectedSMB Service for DSM 7.2, SMB Service for DSM 7.1, SRM 1.3, BeeStation OS 1.3
Fixed version(s)4.15.13-2502 or above, 4.15.9-0644 or above
Moderate2025-03-14

Synology-SA-25:04 SRM

Multiple path traversal issues in SRM 1.3 allowed remote authenticated users to read metadata or read/write limited files.

AffectedSRM 1.3
Fixed version(s)SRM 1.3.1-9346-13 or above