Synology-SA-26:11 Synology MailPlus Server

Publish Time: UTC+8

Last Updated: UTC+8

Severity
Critical
Status
Resolved

Abstract

Synology has released a security update for the Synology MailPlus Server package in DSM to address multiple vulnerabilities :
      • CVE-2026-13136 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.
      • CVE-2025-15660 (ZDI-CAN-28554) allows adjacent attackers to read or write arbitrary files and conduct denial-of-service attacks.
      • CVE-2026-13135 (ZDI-CAN-28485) allows remote attackers to access internal services.

Please refer to the 'Affected Products' table for the corresponding updates.

Affected Products

Product Severity Fixed Release Availability
Synology MailPlus Server for DSM 7.3 Critical Upgrade to 4.0.1-31663 or above.
Synology MailPlus Server for DSM 7.2.2 Critical Upgrade to 4.0.1-21663 or above.
Synology MailPlus Server for DSM 7.2.1 Critical Upgrade to 4.0.1-21663 or above.

Mitigation

None

Detail

Acknowledgement

  • gcali (_gcali) working with Trend Micro Zero Day Initiative

  • ABBA Labs

Reference

Revision

Revision Date Description
1 2026-06-26 Initial public release.