Synology MailPlus Server Multiple Critical Vulnerabilities (CVE-2026-13136, CVE-2025-15660, CVE-2026-13135) — Synology-SA-26:11 — Threadlinqs Intelligence
As of 2026-06-27, Synology MailPlus Server Multiple Critical Vulnerabilities (CVE-2026-13136, CVE-2025-15660, CVE-2026-13135) — Synology-SA-26:11 is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-0957 · Severity: CRITICAL · CVSS: 10 · Status: PATCHED · Category: VULNERABILITY
Synology patched three vulnerabilities in MailPlus Server for DiskStation Manager (DSM) 7.3, 7.2.2, and 7.2.1. The most severe, CVE-2026-13136 (CVSS 10.0, CWE-863 Incorrect Authorization), lets
On 26 June 2026 Synology published security advisory Synology-SA-26:11 disclosing three vulnerabilities in MailPlus Server, the mail-server package that turns a Synology NAS into private email infrastructure. The advisory bundles two newly assigned 2026 CVEs and one 2025 CVE that was reported through Trend Micro's Zero Day Initiative (ZDI).
The headline issue, CVE-2026-13136, is an Incorrect Authorization weakness (CWE-863) rated CVSS 3.1 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Because of faulty authorization checks, a remote, unauthenticated attacker reaching the MailPlus Server over the network can read and write arbitrary files on the host and trigger denial-of-service conditions. The Scope:Changed metric and the maximum 10.0 score indicate the flaw allows the attacker to break out of MailPlus' security authority and affect resources beyond the vulnerable component — i.e., the underlying DSM host filesystem.
CVE-2025-15660 (tracked by ZDI as ZDI-CAN-28554) stems from use of a cryptographically weak pseudo-random number generator (CWE-338). It is rated CVSS 3.1 9.6 (AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Because the affected security tokens or identifiers are generated with a predictable PRNG, an attacker on an adjacent network (AV:A) can predict or brute-force those values to read/write arbitrary files and cause DoS, again with Scope:Changed impact on the host.
CVE-2026-13135 (ZDI-CAN-28485) is an Improper Restriction of Communication Channel to Intended Endpoints weakness (CWE-923) rated CVSS 3.1 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). A remote attacker can use MailPlus Server as a pivot to reach internal services that should not be exposed, yielding limited confidentiality impact (an SSRF-style internal-service-access primitive).
All three issues affect MailPlus Server running on DSM 7.3, 7.2.2, and 7.2.1. Synology fixed them in MailPlus Server 4.0.1-31663 (for DSM 7.3) and 4.0.1-21663 (for DSM 7.2.2 and 7.2.1). The advisory states there is no available mitigation other than upgrading, making patch deployment the only protective action. As of disclosure, full technical details remained under embargo and no in-the-wild exploitation had been reported, but the exposed attack surface is significant: Bitsight's Groma internet-wide scanning identified over 2,100 internet-facing MailPlus Server deployments, concentrated in Germany, South Korea, China, Taiwan, and the United States. The combination of a CVSS 10.0 unauthenticated arbitrary-file-write/DoS flaw, a large internet-exposed footprint, and no mitigation short of patching makes this an upgrade-driven priority for any SOC protecting Synology MailPlus infrastructure.
Synology credited the discoveries to researcher 'gcali' working with Trend Micro's Zero Day Initiative — which tracked CVE-2025-15660 as ZDI-CAN-28554 and CVE-2026-13135 as ZDI-CAN-28485 — as well as to ABBA Labs. The advisory rated CVE-2026-13136 and CVE-2025-15660 as Critical and CVE-2026-13135 as Moderate. From a defensive standpoint the arbitrary-file-write primitive (CVE-2026-13136 / CVE-2025-15660) is the highest-risk capability: an attacker who can write to the DSM host filesystem could drop a web shell or backdoor for persistence, so file-integrity monitoring of the MailPlus Server and DSM web roots is the key compensating control until patches are applied.
Weaknesses (CWE)
CWE-863, CWE-338, CWE-923
Target sectors: small-business, managed-service-providers, technology, education, government
Target regions: Europe, Asia, North America
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-13136, CVE-2025-15660, CVE-2026-13135, T1595, T1590, T1588, T1190, T1133, T1203, T1505, T1211, T1110, T1083