CameraRisk

Synology VS960HD

cpe:2.3:*:synology:vs960hd

Vendor
Synology
Device type
Not derivable from CPE
Published vulnerabilities
23
In CISA KEV
1 KEV
Affected versions recorded
2
Data last built
5 September 2026

Security summary

23 published vulnerabilities affect this product according to NVD. 1 of them is in CISA's Known Exploited Vulnerabilities catalogue, which means confirmed exploitation in the wild.

Exploited: CVE-2021-3156.

Experimental risk indicator

Components are shown separately and deliberately not combined into a single number. Two of the six inputs below have no public source for any product on this site; a composite built without them would be a guess wearing a decimal point.

Known vulnerability count 23 bar saturates at 20
Highest published severity 9.8 CRITICAL
Confirmed exploitation yes 1 in CISA KEV
Exploitation probability EPSS >99.9% (highest)
Lifecycle status no source
Deployed exposure not measurable from public data

Published vulnerabilities

CVEPublishedCVSS SeverityEPSSFlags
CVE-2021-26567 2021-02-26 7.8 high 1.1% Vendor advisory
CVE-2021-26566 2021-02-26 9.0 critical 1.5% Exploit refVendor advisory
CVE-2021-26565 2021-02-26 5.9 medium 0.7% Exploit refVendor advisory
CVE-2021-26564 2021-02-26 8.7 high 0.7% Exploit refVendor advisory
CVE-2021-26563 2021-02-26 6.7 medium 0.5% Exploit refVendor advisory
CVE-2021-26562 2021-02-26 8.1 high 1.9% Exploit refVendor advisory
CVE-2021-26561 2021-02-26 8.1 high 2.0% Exploit refVendor advisory
CVE-2021-26560 2021-02-26 7.4 high 0.7% Exploit refVendor advisory
CVE-2021-3156 2021-01-26 7.8 high >99.9% KEVExploit refVendor advisory
CVE-2019-9518 2019-08-13 7.5 high 25.4%
CVE-2019-9517 2019-08-13 7.5 high 27.9% Vendor advisory
CVE-2019-9516 2019-08-13 6.5 medium 56.3%
CVE-2019-9515 2019-08-13 7.5 high 87.4%
CVE-2019-9514 2019-08-13 7.5 high 82.8%
CVE-2019-9513 2019-08-13 7.5 high 81.6%
CVE-2019-9511 2019-08-13 7.5 high 59.5% Vendor advisory
CVE-2019-3870 2019-04-09 6.1 medium 0.6% Vendor advisory
CVE-2018-1160 2018-12-20 9.8 critical 86.5% Exploit ref
CVE-2018-13281 2018-10-31 4.3 medium 1.2% Vendor advisory
CVE-2018-7185 2018-03-06 7.5 high 9.0% Vendor advisory
CVE-2018-7184 2018-03-06 7.5 high 8.5%
CVE-2018-7170 2018-03-06 5.3 medium 2.7%
CVE-2017-5753 2018-01-04 5.6 medium 93.8% Exploit refVendor advisory

Affected versions

Version strings recorded by NVD against this product. These are the versions named in CPE match rules, not a complete firmware history โ€” a version absent here has not been cleared, it has simply never been named in a CVE record.

Ranges: < 2.2.3-1505 ยท < 2.3.6-1720

What this page does not tell you

There is no public dataset of end-of-support dates, default credentials or shipped network services for this product, so those fields are absent rather than estimated. Whether any of these vulnerabilities is exploitable in your deployment depends on firmware version, configuration and network position โ€” none of which is knowable from here.

For the vendor's own advisories, see Synology.

Other Synology products

Vulnerability records from the National Vulnerability Database, matched to this product by CPE. Exploitation status from CISA KEV 2026.09.04. Exploitation probability from FIRST EPSS, 2026-09-04. Product name derived mechanically from the CPE identifier. See methodology.