CVE-2025-30028: Synology Active Backup For Business

High severity, CVSS 8.6. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files.

Affected products

  • Synology Active Backup For Business: version 2.7.1-23234 only; version 2.7.1-13234 only; version 2.7.1-3234 only

Published 2026-05-27. Last modified 2026-10-07.