CVE-2026-40537 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 PersonMail API server-side request forgery
A vulnerability classified as problematic was found in Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1. This affects an unknown part of the component PersonMail API. The manipulation results in server-side request forgery.
This vulnerability is reported as CVE-2026-40537. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.VulDB Recent EntriesRead More