CVE-2026-40530 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 User API crlf injection
A vulnerability identified as very critical has been detected in Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1. This affects an unknown function of the component User API. This manipulation causes crlf injection.
This vulnerability is tracked as CVE-2026-40530. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.VulDB Recent EntriesRead More