#VU126272 Improper Certificate Validation in DiskStation Manager (DSM) - CVE-2026-40539
Published: April 16, 2026
DiskStation Manager (DSM)
Synology Inc.
Description
The vulnerability allows a remote attacker to read or write arbitrary files and cause a denial of service.
The vulnerability exists due to improper certificate validation in DSM when establishing adjacent-network connections. A remote attacker can perform a man-in-the-middle attack to read or write arbitrary files and cause a denial of service.
User interaction is required.