# Synology MailPlus Server flaws enable remote attacks

Published: 2026-06-30 · Severity: medium
Canonical: https://vorant.io/reports/b84263ef-7172-5b5a-be0b-89ef674d4cba/synology-mailplus-server-flaws-enable-remote-attacks

> Multiple vulnerabilities in Synology MailPlus Server allow remote attackers to compromise data integrity and confidentiality or cause denial of service.

The French national cybersecurity agency CERT-FR has issued an advisory regarding multiple security vulnerabilities in Synology MailPlus Server. The flaws affect versions prior to 4.0.1-21663 for DSM 7.2.1 and 7.2.2, and versions prior to 4.0.1-31663 for DSM 7.3.

The vulnerabilities enable remote attackers to compromise the integrity and confidentiality of data, as well as trigger denial-of-service conditions. Three CVEs have been assigned to track these issues: CVE-2025-15660, CVE-2026-13135, and CVE-2026-13136. Organizations running affected versions of Synology MailPlus Server should apply the patches provided by the vendor immediately to remediate these security weaknesses.

## Mentioned in this report

- Vulnerabilities: CVE-2025-15660, CVE-2026-13135, CVE-2026-13136

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0819

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/b84263ef-7172-5b5a-be0b-89ef674d4cba/synology-mailplus-server-flaws-enable-remote-attacks.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
