Multiple Vulnerabilities Discovered in Synology MailPlus Server

The CERT‑FR has identified several vulnerabilities in Synology MailPlus Server that could allow attackers to cause remote denial of service, compromise data confidentiality, and compromise data integrity. The vulnerabilities affect versions older than 4.0.1‑21663 on DSM 7.2.1 and 7.2.2, and older than 4.0.1‑31663 on DSM 7.3. The risks include data integrity loss, data confidentiality breach, and remote denial of service. Users should consult the Synology security advisory (Synology_SA_26_11, 26 June 2026) for patches. The advisory lists CVE‑2025‑15660, CVE‑2026‑13135, and CVE‑2026‑13136. Applying the latest updates will mitigate the identified threats. These findings were first reported by Synology in their own security bulletin, which outlines the necessary fixes and best practices for administrators.

Summary of content from

source

Made by AI. If you spot anything of concern write us at contact@cybach.com. We’ll promptly correct irregularities.


Posted