Synology MailPlus Server flaws enable remote attacks
Multiple vulnerabilities in Synology MailPlus Server allow remote attackers to compromise data integrity and confidentiality or cause denial of service.
The French national cybersecurity agency CERT-FR has issued an advisory regarding multiple security vulnerabilities in Synology MailPlus Server. The flaws affect versions prior to 4.0.1-21663 for DSM 7.2.1 and 7.2.2, and versions prior to 4.0.1-31663 for DSM 7.3.
The vulnerabilities enable remote attackers to compromise the integrity and confidentiality of data, as well as trigger denial-of-service conditions. Three CVEs have been assigned to track these issues: CVE-2025-15660, CVE-2026-13135, and CVE-2026-13136. Organizations running affected versions of Synology MailPlus Server should apply the patches provided by the vendor immediately to remediate these security weaknesses.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0819
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free