Synology issues critical fix for MailPlus Server vulnerabilities
ID: e643bace-8bca-5117-bc0b-8719e92290b6
STIX ID: report--e643bace-8bca-5117-bc0b-8719e92290b6
Feed Name: Help Net Security
Threat Score
Synology patched three critical vulnerabilities in MailPlus Server (CVE-2026-13136, CVE-2026-13135, CVE-2025-15660) that could enable arbitrary file read/write, denial-of-service, and unauthorized access to internal services; users on DSM 7.3, 7.2.2, or 7.2.1 should upgrade to MailPlus Server 4.0.1-31663 because no mitigations are available. Bitsight’s scanning shows over 2,100 internet-facing deployments are exposed, mainly in Germany, Korea, China, Taiwan, and the US.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
