Výsledky hledání

výrobce: Synology× v celém archivu zrušit filtry

5 karet z 5 položek CZ · EN/orig

1

Synology DSM — Multiple Critical Vulnerabilities

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-13684, CVE-2026-13639, CVE-2026-13673, CVE-2026-6205, CVE-2026-13635, CVE-2026-13623, CVE-2026-13666, CVE-2026-13683, Summary: Synology released a security update for DSM on 18 September 2026 addressing multiple vulnerabilities, including two CVSS 9.8 flaws that can allow remote attackers to read/write arbitrary files and cause denial of service.

EPSS 0.01 CVSS 9.8 CVE-2026-13623 CVE-2026-13635 CVE-2026-13639 CVE-2026-13666 CVE-2026-13673 CVE-2026-13683 CVE-2026-13684 CVE-2026-6205 Synology FI

tg: zranitelnost tp: DDoS

· NCSC-FI · Synology DSM — Multiple Critical Vulnerabilities

1

Aggiornamenti di sicurezza per prodotti Synology

Aggiornamenti di sicurezza sanano una vulnerabilità con gravità "critica" presente in Synology Chat Server, componente del prodotto DiskStation Manager (DSM) di Synology. Tale vulnerabilità, qualora sfruttata, potrebbe consentire a un utente autenticato remoto di leggere o scrivere file arbitrari e compromettere la disponibilità del sistema.

EPSS 0.00 CVE-2026-40541 Synology IT

tg: zranitelnost

· CSIRT Itálie (ACN) · Aggiornamenti di sicurezza per prodotti Synology

2

ZDI-26-423: Synology DiskStation DS925+ MailPlus Redis Weak Cryptography for Passwords Remote Code Execution Vulnerability

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology DiskStation DS925+ devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2025-15660.

CVSS 8.8 CVE-2025-15660 Synology US

· Zero Day Initiative · ZDI-26-423: Synology DiskStation DS925+ MailPlus Redis Weak Cryptography for Passwords Remote Code Execution Vulnerability

ZDI-26-424: Synology DiskStation DS925+ MailPlus Improper Restriction of Communication Channel to Intended Endpoints Vulnerability

This vulnerability allows network-adjacent attackers to access the Redis instance on affected installations of Synology DiskStation DS925+ devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.3. The following CVEs are assigned: CVE-2026-13135.

CVSS 4.3 CVE-2026-13135 Synology US

· Zero Day Initiative · ZDI-26-424: Synology DiskStation DS925+ MailPlus Improper Restriction of Communication Channel to Intended Endpoints Vulnerability

1

VerdantBamboo: Just Another BRICKSTORM in the Firewall

In September 2025, Volexity conducted an incident response engagement that began after suspicious network traffic was observed from a Linux-based virtual machine appliance on a customer’s network. The virtual machine was an Egnyte Storage Sync system, which is designed to facilitate syncing local on-premise files with the cloud. Volexity discovered that instead of connecting to a domain affiliated with Egnyte, the appliance was connecting to a threat-actor-controlled domain behind Cloudflare IP…

Egnyte Microsoft Synology Cloudflare US

· Volexity · VerdantBamboo: Just Another BRICKSTORM in the Firewall