Official sources used

Synology security advisories and QNAP security advisories/download center

This page keeps the editorial layer narrow: highlight the most useful official advisories, surface the fixed builds plainly, and link readers back to the vendor for the actual update path.

Synology2026-06-26

Synology-SA-26:11 MailPlus Server security update

Synology published a Critical MailPlus Server package advisory for DSM and gave exact fixed package builds across DSM 7.3, 7.2.2, and 7.2.1 instead of leaving admins to infer the upgrade target.

Fixed versionsMailPlus Server 4.0.1-31663+ for DSM 7.3; 4.0.1-21663+ for DSM 7.2.2 and DSM 7.2.1
Why it mattersA current Critical Synology package advisory with exact fixed builds strengthens the site's NAS lane without drifting into vague release churn.
Synology2026-05-26

Synology-SA-26:10 Chat Server security update

Synology published an Important package advisory for Synology Chat Server in DSM and gave one exact fixed build across DSM 7.3, 7.2.2, and 7.2.1 instead of leaving package admins to infer upgrade targets.

Fixed versionsSynology Chat Server 2.4.5-22148+ for DSM 7.3, DSM 7.2.2, and DSM 7.2.1
Why it mattersIt deepens the site's Synology NAS lane with a newer package-level record that still has excellent fixed-version clarity.
Synology2026-04-15

Synology-SA-26:06 DSM security update

Synology published a broad DSM advisory covering 11 vulnerabilities and, importantly, spelled out minimum fixed releases across DSM 7.3, 7.2.2, and 7.2.1 instead of leaving operators to infer patch targets.

Fixed versionsDSM 7.3.2-86009-2+, DSM 7.2.2-72806-7+, DSM 7.2.1-69057-10+
Why it mattersIt is exactly the kind of high-signal NAS advisory that makes the site more useful and more credible as a fixed-version reference asset.
Synology2026-03-19

Synology-SA-26:03 DSM critical security update

Synology warned that CVE-2026-32746 in GNU Inetutils telnetd could allow unauthenticated remote command execution and published fixed DSM builds by branch.

Fixed versionsDSM 7.3.2-86009-3+, DSM 7.2.2-72806-8+, DSM 7.2.1-69057-11+
Why it mattersCritical DSM advisories with explicit fixed builds strengthen the site's claim that it highlights patch targets, not just headlines.
Synology2025-11-19

Synology-SA-25:14 DSM (PWN2OWN 2025) auth-bypass update

Synology published a PWN2OWN-linked DSM advisory for an SSO authentication-bypass issue and gave exact fixed releases for DSM 7.3 and DSM 7.2.2 instead of vague "update soon" guidance.

Fixed versionsDSM 7.3.1-86003-1+, DSM 7.2.2-72806-5+; DSM 7.2.1 is not affected
Why it mattersIt adds a durable core-DSM auth-bypass record with clean fixed-version clarity and visible PWN2OWN search intent.
Synology2025-05-29

Synology-SA-25:07 SMB Service

Synology says this SMB Service issue could allow remote authenticated users to write to limited files, and it published fixed package versions by DSM track.

Fixed versionsDSM 7.2: 4.15.13-2502 or above; DSM 7.1: 4.15.9-0644 or above
Why it mattersIt is a good example of the kind of package-level advisory Synology handles clearly enough for operators to act on quickly.
QNAP2026-06-17

QSA-26-10 vulnerabilities in QTS, QuTS hero, QuTS cloud, and QVP

QNAP published a broad Important advisory covering QTS, QuTS hero, QuTS cloud, and QVP, and unlike weaker mitigation-only notices it also gives exact fixed versions across every affected platform line.

Fixed versionsQTS 5.2.9.3499, QuTS hero h5.2.9, QuTS cloud C5.2.9, QVP 2.8.0
Why it mattersThis is the kind of current QNAP advisory that strengthens the site's NAS utility because operators can move directly from issue awareness to a concrete minimum target version.
QNAP2026-05-11

QSA-26-17 Dirty Frag Linux kernel privilege-escalation advisory

QNAP says the Linux kernel "Dirty Frag" flaw affects all QNAP x86-based NAS models, all ARM64-based NAS models, all QuTS hero NAS models, and all QuTScloud instances. After first publishing mitigations, QNAP marked the advisory resolved on May 25, 2026 and now tells operators to install the latest firmware.

Current statusResolved on 2026-05-25; install the latest firmware. QNAP still does not publish branch-specific minimum fixed builds in the advisory.
Why it mattersThis is a good example of a broad-scope advisory that stayed worth indexing across both the mitigation-first phase and the later resolved-state update.
QNAP2026-01-03

QSA-25-50 multiple vulnerabilities in QTS and QuTS hero

QNAP published a broad advisory covering current NAS operating system branches and provided fixed builds across both QTS and QuTS hero tracks.

Fixed buildsQTS 5.2.7.3256 build 20250913+, QuTS hero h5.2.7.3256 build 20250913+, QuTS hero h5.3.1.3250 build 20250912+
Why it mattersThese broader advisories are useful because they collapse many vulnerabilities into a concrete minimum target version by branch.
QNAP2025-11-08

QSA-25-45 multiple vulnerabilities in QTS and QuTS hero (PWN2OWN 2025)

QNAP ties this advisory to PWN2OWN 2025 and lists command injection, SQL injection, authentication bypass, and memory handling issues across supported tracks.

Fixed buildsQTS 5.2.7.3297 build 20251024+, QuTS hero h5.2.7.3297 build 20251024+, QuTS hero h5.3.1.3292 build 20251024+
Why it mattersPWN2OWN-linked advisories tend to attract search demand and are strong candidates for durable static coverage.
QNAP2025-08-29

QSA-25-21 multiple vulnerabilities in QTS and QuTS hero

QNAP lists a broad mix of command injection, path traversal, denial-of-service, and memory corruption issues and again gives a direct fixed-build target by branch.

Fixed buildsQTS 5.2.5.3145 build 20250526+, QuTS hero h5.2.5.3138 build 20250519+
Why it mattersIt shows why QNAP is worth covering: the advisories are busy, but still structured enough to normalize cleanly.