Critical2026-06-26
Synology-SA-26:11 MailPlus Server security update
Synology published a Critical MailPlus Server package advisory for DSM after disclosing file access, denial-of-service, and internal-service exposure issues, with exact fixed package releases across current DSM branches.
AffectedSynology MailPlus Server for DSM 7.3, DSM 7.2.2, DSM 7.2.1
Fixed version(s)MailPlus Server 4.0.1-31663+ for DSM 7.3; 4.0.1-21663+ for DSM 7.2.2 and 7.2.1
Important2026-05-26
Synology-SA-26:10 Chat Server security update
Synology published an Important Chat Server package advisory for DSM after disclosing three vulnerabilities affecting file access and service stability, with one fixed package build across the current DSM branches it supports.
AffectedSynology Chat Server for DSM 7.3, DSM 7.2.2, DSM 7.2.1
Fixed version(s)Synology Chat Server 2.4.5-22148+ for DSM 7.3 and DSM 7.2.x
Important2026-04-15
Synology-SA-26:06 DSM security update
Synology published a broad DSM security advisory covering 11 vulnerabilities, with explicit fixed releases across current supported DSM branches.
AffectedDSM 7.3, DSM 7.2.2, DSM 7.2.1
Fixed version(s)DSM 7.3.2-86009-2+, DSM 7.2.2-72806-7+, DSM 7.2.1-69057-10+
Moderate2026-03-31
Synology-SA-26:04 Mail Station security update
Synology published a Mail Station package security advisory for DSM after disclosing that CVE-2026-5129 may allow remote authenticated users to read or write limited files.
AffectedMail Station for DSM 7.3, Mail Station for DSM 7.2.2, Mail Station for DSM 7.2.1
Fixed version(s)Mail Station 30000001.3.19-20332+ for DSM 7.3 and 7.2.x
Critical2026-03-19
Synology-SA-26:03 DSM critical security update
Synology disclosed a critical DSM update for GNU Inetutils telnetd after warning that CVE-2026-32746 may allow unauthenticated remote attackers to execute arbitrary commands.
AffectedDSM 7.3, DSM 7.2.2, DSM 7.2.1, DSMUC 3.1
Fixed version(s)DSM 7.3.2-86009-3+, DSM 7.2.2-72806-8+, DSM 7.2.1-69057-11+
Moderate2026-02-09
Synology-SA-26:01 Storage Manager
Synology released a Storage Manager package security update for DSM 7.3 and DSM 7.2.x after disclosing a local information exposure issue.
AffectedStorage Manager for DSM 7.3, Storage Manager for DSM 7.2.2, Storage Manager for DSM 7.2.1
Fixed version(s)1.0.1-1100 or above
Important2025-11-19
Synology-SA-25:14 DSM (PWN2OWN 2025) auth-bypass update
Synology published a PWN2OWN-linked DSM advisory for an SSO authentication-bypass issue that could let remote attackers bypass authentication with prior knowledge of a distinguished name.
AffectedDSM 7.3, DSM 7.2.2
Fixed version(s)DSM 7.3.1-86003-1+, DSM 7.2.2-72806-5+; DSM 7.2.1 is not affected
Moderate2025-09-16
Synology-SA-25:11 Safe Access
Safe Access for SRM 1.3 received a security update for a vulnerability that could allow remote authenticated administrator-level users to read or write limited files.
AffectedSafe Access for SRM 1.3
Fixed version(s)1.3.1-0329 or above
Moderate2025-08-29
Synology-SA-25:10 RADIUS Server
RADIUS Server for SRM 1.3 received a fix for an XSS issue that could let remote authenticated administrator-level users read or write limited files and conduct limited DoS.
AffectedRADIUS Server for SRM 1.3
Fixed version(s)3.0.27-0139 or above
Moderate2025-05-29
Synology-SA-25:07 SMB Service
Synology disclosed an SMB Service issue where remote authenticated users could write to limited files; DSM packages received fixed builds and SRM/BeeStation remained ongoing at publication time.
AffectedSMB Service for DSM 7.2, SMB Service for DSM 7.1, SRM 1.3, BeeStation OS 1.3
Fixed version(s)4.15.13-2502 or above, 4.15.9-0644 or above
Moderate2025-03-14
Synology-SA-25:04 SRM
Multiple path traversal issues in SRM 1.3 allowed remote authenticated users to read metadata or read/write limited files.
AffectedSRM 1.3
Fixed version(s)SRM 1.3.1-9346-13 or above