Back Heise.De Vulnerabilities in Synology MailPlus Server allow attackers to pass
If attackers successfully exploit security vulnerabilities in Synology MailPlus Server, they can access files or trigger crashes via DoS attacks, among other things. The manufacturer currently has no warnings ongoing attacks.
In a warning message, the developers list a total of three vulnerabilities . Two of them are classified as “ critical ” (CVE-2025-15660), one (CVE-2026-13136) has the maximum CVSS score of 10 out of 10. In both cases, unauthorized file access and DoS attacks are possible.
The third vulnerability (CVE-2026-13135) is classified as “ medium. ” Here, attackers can access internal, undescribed services.
The developers assure that the security issues in MailPlus Server 4.0.1-21663 for DSM 7.2.1, 7.2.2, and 7.3 have been resolved.
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
