Synology has issued critical security updates for its MailPlus Server package running on DiskStation Manager (DSM), addressing multiple high-impact vulnerabilities that could allow attackers to tamper with files, access internal services, and trigger denial-of-service (DoS) conditions.
The most severe issue, tracked as CVE-2026-13136, carries a CVSS v3.1 score of 10.0, indicating maximum severity. The advisory highlights three vulnerabilities, including two critical flaws that significantly impact confidentiality, integrity, and availability.
Critical Synology MailPlus Server Flaw
The flaw stems from improper authorization (CWE-863) and allows unauthenticated remote attackers to read or write arbitrary files on affected systems. Successful exploitation could also enable full service disruption through denial-of-service attacks.
Another critical vulnerability, CVE-2025-15660 (ZDI-CAN-28554), has a CVSS score of 9.6. This flaw is associated with the use of a cryptographically weak pseudo-random number generator (CWE-338).
It enables an adjacent attacker with network proximity to perform arbitrary file operations and disrupt services. Although it requires network adjacency, the lack of authentication significantly increases the risk of exploitation in shared or enterprise environments.
A third vulnerability, CVE-2026-13135 (ZDI-CAN-28485), is rated moderate with a CVSS score of 5.3.
This issue arises from improper restrictions on communication channels (CWE-923), allowing remote attackers to access internal services. While less severe, it could serve as a stepping stone for lateral movement or further compromise.
Affected Products and Fixes
The vulnerabilities impact multiple versions of Synology MailPlus Server across DSM releases. Synology has released patched versions, and users are strongly urged to upgrade immediately:
- DSM 7.3: Upgrade to MailPlus Server version 4.0.1-31663 or later
- DSM 7.2.2: Upgrade to version 4.0.1-21663 or later
- DSM 7.2.1: Upgrade to version 4.0.1-21663 or later
No workarounds or mitigations are available, making patching the only effective defense. Given the combination of remote exploitability, lack of authentication, and elevated privileges, CVE-2026-13136 represents a critical risk for exposed MailPlus Server instances.
Attackers could potentially manipulate email storage, exfiltrate sensitive communications, or render services unavailable. In enterprise deployments where MailPlus is integrated into internal communication workflows, exploitation could lead to widespread disruption and data compromise.
The presence of an adjacent network attack vector in CVE-2025-15660 further expands the threat landscape, particularly in segmented or partially trusted environments.
Mitigation
Synology published the advisory on June 26, 2026, marking the initial public release of these findings. Organizations using Synology MailPlus Server should prioritize immediate patching, especially for internet-facing deployments.
Administrators should also review system logs for anomalous activity, restrict unnecessary network exposure, and implement network segmentation where possible to reduce attack surfaces.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.