CVE-2026-3091: Synology Presto Client

High severity, CVSS 7.3. EPSS: 0.2% chance of exploitation in the next 30 days.

An uncontrolled search path element vulnerability in Synology Presto Client before 2.1.3-0672 allows local users to read or write arbitrary files and conduct denial-of-service during installation by placing a malicious DLL in advance in the same directory as the installer.

Affected products

  • Synology Presto Client: before 2.1.3-0672 (fixed in 2.1.3-0672)

Published 2026-02-24. Last modified 2026-06-17.