Synology MailPlus Server Multiple Critical Vulnerabilities (CVE-2026-13136, CVE-2025-15660, CVE-2026-13135) — Synology-SA-26:11

Synology MailPlus Server Multiple Critical Vulnerabilities (TL-2026-0957), also tracked as Synology-SA-26:11, is a critical-severity software vulnerability scored CVSS 10, first published 2026-06-27. It has no confirmed attribution, affects Synology MailPlus Server (DSM 7.3), references 3 CVEs (CVE-2026-13136, CVE-2025-15660, CVE-2026-13135), maps to 17 MITRE ATT&CK techniques (T1005, T1046, T1083), and is covered by 9 detection rules and 18 indicators of compromise.

Key facts for TL-2026-0957

Threat ID
TL-2026-0957
Also known as
Synology-SA-26:11, ZDI-CAN-28554, ZDI-CAN-28485
Severity
CRITICAL
CVSS
10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
2026-06-27
Last reviewed
2026-06-27
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
small-business, managed-service-providers, technology, education, government
Target regions
Europe, Asia, North America
Detection rules
9
Indicators of compromise
18

Synology patched three vulnerabilities in MailPlus Server for DiskStation Manager (DSM) 7.3, 7.2.2, and 7.2.1. The most severe, CVE-2026-13136 (CVSS 10.0, CWE-863 Incorrect Authorization), lets unauthenticated remote attackers read/write arbitrary files and cause denial of service. CVE-2025-15660 (CVSS 9.6, CWE-338 weak PRNG) gives adjacent attackers the same file and DoS impact, and CVE-2026-13135 (CVSS 5.3, CWE-923) lets remote attackers reach internal services. Fixed in MailPlus Server 4.0.1-31663 (DSM 7.3) / 4.0.1-21663 (DSM 7.2.2 and 7.2.1); no mitigation exists short of upgrading.

How Synology MailPlus Server Multiple Critical Vulnerabilities works

On 26 June 2026 Synology published security advisory Synology-SA-26:11 disclosing three vulnerabilities in MailPlus Server, the mail-server package that turns a Synology NAS into private email infrastructure. The advisory bundles two newly assigned 2026 CVEs and one 2025 CVE that was reported through Trend Micro's Zero Day Initiative (ZDI).

The headline issue, CVE-2026-13136, is an Incorrect Authorization weakness (CWE-863) rated CVSS 3.1 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Because of faulty authorization checks, a remote, unauthenticated attacker reaching the MailPlus Server over the network can read and write arbitrary files on the host and trigger denial-of-service conditions. The Scope:Changed metric and the maximum 10.0 score indicate the flaw allows the attacker to break out of MailPlus' security authority and affect resources beyond the vulnerable component — i.e., the underlying DSM host filesystem.

CVE-2025-15660 (tracked by ZDI as ZDI-CAN-28554) stems from use of a cryptographically weak pseudo-random number generator (CWE-338). It is rated CVSS 3.1 9.6 (AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Because the affected security tokens or identifiers are generated with a predictable PRNG, an attacker on an adjacent network (AV:A) can predict or brute-force those values to read/write arbitrary files and cause DoS, again with Scope:Changed impact on the host.

CVE-2026-13135 (ZDI-CAN-28485) is an Improper Restriction of Communication Channel to Intended Endpoints weakness (CWE-923) rated CVSS 3.1 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). A remote attacker can use MailPlus Server as a pivot to reach internal services that should not be exposed, yielding limited confidentiality impact (an SSRF-style internal-service-access primitive).

All three issues affect MailPlus Server running on DSM 7.3, 7.2.2, and 7.2.1. Synology fixed them in MailPlus Server 4.0.1-31663 (for DSM 7.3) and 4.0.1-21663 (for DSM 7.2.2 and 7.2.1). The advisory states there is no available mitigation other than upgrading, making patch deployment the only protective action. As of disclosure, full technical details remained under embargo and no in-the-wild exploitation had been reported, but the exposed attack surface is significant: Bitsight's Groma internet-wide scanning identified over 2,100 internet-facing MailPlus Server deployments, concentrated in Germany, South Korea, China, Taiwan, and the United States. The combination of a CVSS 10.0 unauthenticated arbitrary-file-write/DoS flaw, a large internet-exposed footprint, and no mitigation short of patching makes this an upgrade-driven priority for any SOC protecting Synology MailPlus infrastructure.

Synology credited the discoveries to researcher 'gcali' working with Trend Micro's Zero Day Initiative — which tracked CVE-2025-15660 as ZDI-CAN-28554 and CVE-2026-13135 as ZDI-CAN-28485 — as well as to ABBA Labs. The advisory rated CVE-2026-13136 and CVE-2025-15660 as Critical and CVE-2026-13135 as Moderate. From a defensive standpoint the arbitrary-file-write primitive (CVE-2026-13136 / CVE-2025-15660) is the highest-risk capability: an attacker who can write to the DSM host filesystem could drop a web shell or backdoor for persistence, so file-integrity monitoring of the MailPlus Server and DSM web roots is the key compensating control until patches are applied.

MITRE ATT&CK techniques used in TL-2026-0957

Collection

T1005 Data from Local System; T1114 Email Collection

Discovery

T1046 Network Service Discovery; T1083 File and Directory Discovery

Credential Access

T1110 Brute Force

Initial Access

T1133 External Remote Services; T1190 Exploit Public-Facing Application

Execution

T1203 Exploitation for Client Execution

Lateral Movement

T1210 Exploitation of Remote Services

Defense Evasion

T1211 Exploitation for Stealth

Impact

T1498 Network Denial of Service; T1499 Endpoint Denial of Service; T1565 Data Manipulation

Persistence

T1505 Server Software Component

Resource Development

T1588 Obtain Capabilities

Reconnaissance

T1590 Gather Victim Network Information; T1595 Active Scanning

Affected products and versions in Synology MailPlus Server Multiple Critical Vulnerabilities

  • Synology — MailPlus Server (DSM 7.3)
    Vulnerable versions: before 4.0.1-31663
    Fixed in: 4.0.1-31663
  • Synology — MailPlus Server (DSM 7.2.2)
    Vulnerable versions: before 4.0.1-21663
    Fixed in: 4.0.1-21663
  • Synology — MailPlus Server (DSM 7.2.1)
    Vulnerable versions: before 4.0.1-21663
    Fixed in: 4.0.1-21663

Remediation for Synology MailPlus Server Multiple Critical Vulnerabilities

Patches

  • MailPlus Server 4.0.1-31663 or above (DSM 7.3)
  • MailPlus Server 4.0.1-21663 or above (DSM 7.2.2)
  • MailPlus Server 4.0.1-21663 or above (DSM 7.2.1)

Immediate actions

  • Upgrade MailPlus Server to 4.0.1-31663 (DSM 7.3) or 4.0.1-21663 (DSM 7.2.2 / 7.2.1) immediately — Synology states there is NO mitigation other than upgrading
  • Identify all internet-facing MailPlus Server instances and confirm the installed package version against the fixed builds
  • Restrict network exposure of the MailPlus Server admin/web interface to trusted networks while patching is in progress

Workarounds

  • No vendor-provided mitigation exists; reduce exposure by removing internet reachability of MailPlus Server until patched

Longer-term hardening

  • Place the NAS mail service behind a reverse proxy or VPN rather than exposing it directly to the internet
  • Enable Synology DSM auto-update for security packages so future MailPlus Server advisories are applied promptly
  • Segment NAS appliances from sensitive internal services to blunt the CVE-2026-13135 internal-service-access pivot
  • Deploy file-integrity monitoring on the DSM host to detect arbitrary-file-write exploitation of CVE-2026-13136 / CVE-2025-15660

CVEs associated with Synology MailPlus Server Multiple Critical Vulnerabilities

CVE-2026-13136, CVE-2025-15660, CVE-2026-13135

Weaknesses (CWE) in Synology MailPlus Server Multiple Critical Vulnerabilities

CWE-863, CWE-338, CWE-923

Timeline of Synology MailPlus Server Multiple Critical Vulnerabilities

  • CVE-2025-15660 reserved; reported to Synology through Trend Micro Zero Day Initiative as ZDI-CAN-28554 (weak PRNG, CWE-338).
  • CVE-2026-13135 (ZDI-CAN-28485) and CVE-2026-13136 reserved for the MailPlus Server authorization and communication-channel flaws.
  • Synology rated CVE-2026-13136 and CVE-2025-15660 'Critical' and CVE-2026-13135 'Moderate' in the advisory's severity column.
  • Help Net Security reported the patches; full technical details remained under embargo and no in-the-wild exploitation was reported at disclosure.
  • Synology credited the discoveries to 'gcali' working with Trend Micro Zero Day Initiative (ZDI-CAN-28554 / ZDI-CAN-28485) and to ABBA Labs in advisory Synology-SA-26:11.
  • Bitsight Groma internet-wide scanning identified over 2,100 internet-facing MailPlus Server deployments, concentrated in Germany, South Korea, China, Taiwan, and the United States.
  • Fixed MailPlus Server 4.0.1-31663 (DSM 7.3) and 4.0.1-21663 (DSM 7.2.2 / 7.2.1) released; Synology states no mitigation exists other than upgrading.
  • Synology published advisory Synology-SA-26:11 disclosing CVE-2026-13136 (CVSS 10.0), CVE-2025-15660 (CVSS 9.6), and CVE-2026-13135 (CVSS 5.3) and released the fixed MailPlus Server builds.
  • Threadlinqs Intelligence documented the threat for SOC remediation tracking and detection coverage.

Sources cited for Synology MailPlus Server Multiple Critical Vulnerabilities

Threats related to Synology MailPlus Server Multiple Critical Vulnerabilities

Detection coverage for TL-2026-0957

As of 2026-06-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0957 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats