CVE-2026-40537 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 PersonMail API server-side request forgery

SecurityVulns

A vulnerability classified as problematic was found in Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1. This affects an unknown part of the component PersonMail API. The manipulation results in server-side request forgery.

This vulnerability is reported as CVE-2026-40537. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is advised.VulDB Recent EntriesRead More