CVE-2025-66592: Synology Active Backup For Business Agent

Medium severity, CVSS 5.6. EPSS: 0.1% chance of exploitation in the next 30 days.

An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.

Affected products

  • Synology Active Backup For Business Agent: before 3.1.0-4967 (fixed in 3.1.0-4967)

Published 2026-05-27. Last modified 2026-10-07.