CVE-2025-13593: Synology Activeprotect Agent

Medium severity, CVSS 5.6. EPSS: 0.1% chance of exploitation in the next 30 days.

Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.

Affected products

  • Synology Activeprotect Agent: before 1.1.0-0439 (fixed in 1.1.0-0439)

Published 2026-05-27. Last modified 2026-10-07.