Synology disclosed three vulnerabilities in MailPlus Server for DiskStation Manager (DSM), including two Critical flaws that can let attackers read or write arbitrary files and trigger denial-of-service conditions. The most severe issue, CVE-2026-13136, carries a CVSS 10.0 rating and can be exploited remotely without authentication, while CVE-2025-15660 can be abused by an adjacent attacker for similar file access and service disruption. A third flaw, CVE-2026-13135, is rated Moderate and can allow remote attackers to access internal services.
The advisory affects MailPlus Server deployments on DSM 7.3, 7.2.2, and 7.2.1. Synology said there is no mitigation or workaround other than upgrading to the fixed releases, directing customers to update to 4.0.1-31663 or 4.0.1-21663 depending on platform version. Organizations using Synology MailPlus Server are being urged to patch immediately because the exposed attack paths include unauthenticated remote exploitation and arbitrary file operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
On 2026-06-26, Synology released advisory SA-26-11 for Synology MailPlus Server on DSM, disclosing three vulnerabilities: CVE-2026-13136, CVE-2025-15660, and CVE-2026-13135. The company directed customers to upgrade to fixed releases 4.0.1-31663 or 4.0.1-21663 and said no mitigation is available aside from applying the updates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesynology.com
Open sourcecwe.mitre.org
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.