CVE-2026-40531
published 2026-09-18CVE-2026-40531: An integer overflow or wraparound vulnerability in File Operation in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2…
PriorityP421medium4.3CVSS 3.1
AVNACLPRLUINSUCNINAL
EPSS
0.33%
26.7th percentile
An integer overflow or wraparound vulnerability in File Operation in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to conduct limited denial-of-service attacks.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| synology | diskstation_manager | >= 7.2.1 < 7.2.1-69057-10 | 7.2.1-69057-10 |
| synology | diskstation_manager | >= 7.2.2 < 7.2.2-72806-7 | 7.2.2-72806-7 |
| synology | diskstation_manager | >= 7.3 < 7.3.2-86009-2 | 7.3.2-86009-2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 File Operation integer overflow (WID-SEC-2026-1125)
vuldb·2026-09-20·CVSS 4.3
CVE-2026-40531 [MEDIUM] Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 File Operation integer overflow (WID-SEC-2026-1125)
A vulnerability has been found in Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 and classified as critical. This affects an unknown part of the component File Operation. This manipulation causes integer overflow.
This vulnerability is handled as CVE-2026-40531. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
GHSA
An integer overflow or wraparound vulnerability in File Operation in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to cond
ghsa_unreviewed·2026-09-18
CVE-2026-40531 [MEDIUM] CWE-190 An integer overflow or wraparound vulnerability in File Operation in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to cond
An integer overflow or wraparound vulnerability in File Operation in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to conduct limited denial-of-service attacks.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-18
Published