Synology released a security update for its SSL VPN Client to fix two Important vulnerabilities, CVE-2021-47960 and CVE-2021-47961, affecting versions before 1.4.5-0684. The company said a remote attacker could exploit the flaws if a user is lured to a crafted web page while the VPN client is running. One issue stems from improper access controls on a local loopback HTTP service, allowing access to sensitive files in the installation directory, including configuration files, certificates, and logs.
The second flaw involves insecure plaintext storage of the client PIN, which can let an attacker read or manipulate PIN data, alter VPN configuration, and potentially intercept later VPN traffic. Synology said no workaround is available and urged customers to upgrade immediately to SSL VPN Client 1.4.5-0684 or later. The vulnerabilities were reported by security researcher Laurent Sibilla.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
A follow-up report described how the patched flaws could expose sensitive local files, reveal or alter PIN data, and potentially enable later VPN traffic interception through rogue configuration changes. The report reiterated that exploitation required user interaction with a malicious web page.
Synology disclosed SA-26-05 on 2026-04-10 and released an update to fix CVE-2021-47960 and CVE-2021-47961 in SSL VPN Client. The company said no workaround was available and instructed customers to upgrade to version 1.4.5-0684 or later.
Security researcher Laurent Sibilla discovered and reported two vulnerabilities in Synology SSL VPN Client, later assigned CVE-2021-47960 and CVE-2021-47961. The issues affected versions before 1.4.5-0684 and could be exploited if a user was lured to a crafted web page while the client was running.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
coalitioninc.com
Open sourcecybersecuritynews.com
Open sourcesynology.com
Open sourcecybersecuritydive.com
Open sourcetheregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.