CRITICAL 9 CVE-2026-40541 Published 28 Aug 2026

Synology Chat Server XSS File Read/Write Vulnerability

Worried this affects one of your servers?

Synology Chat Server before version 2.4.5-22148 is affected by a Cross-Site Scripting (XSS) vulnerability in the domain extraction feature.

Remote authenticated users can exploit this vulnerability to read or write arbitrary files and cause denial-of-service attacks on the DSM.

Reference: CVE-2026-40541 on NVD

← Back to Security News