logo

Synology issues critical fix for MailPlus Server vulnerabilities

ID: e643bace-8bca-5117-bc0b-8719e92290b6

STIX ID: report--e643bace-8bca-5117-bc0b-8719e92290b6

Feed Name: Help Net Security

Threat Score
60/100

Date Published: 2026-06-26

Date Updated: 2026-06-26

Author: Zeljka Zorz

...
...

Synology patched three critical vulnerabilities in MailPlus Server (CVE-2026-13136, CVE-2026-13135, CVE-2025-15660) that could enable arbitrary file read/write, denial-of-service, and unauthorized access to internal services; users on DSM 7.3, 7.2.2, or 7.2.1 should upgrade to MailPlus Server 4.0.1-31663 because no mitigations are available. Bitsight’s scanning shows over 2,100 internet-facing deployments are exposed, mainly in Germany, Korea, China, Taiwan, and the US.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.