Many Synology owners have asked us about the Log4j vulnerability over the last 6 months. Whether you are affected by the Log4j vulnerability or not depends on the applications you run on your Synology
If you only use Synology Core packages, you are safe. Synology DSM does not use log4j 2, so if your NAS has only Synology Core packages, you are safe.
If you have third-party apps installed, or are running virtualized apps on your Synology, or are running Docker apps on your Synology, you may have an app that uses log4j 2. In this case, you should perform an app audit - make a list of all the apps you use and check if any of them use log4j. It is also a good idea to remove the applications that you do not use.