Security News

Cybersecurity news aggregator

🔄
CRITICAL Updates Help Net Security

Synology issues critical fix for MailPlus Server vulnerabilities

Synology has patched three critical vulnerabilities in its MailPlus Server software, including CVE-2026-13136 which allows arbitrary file read/write and DoS via faulty authorization checks, and CVE-2026-13135 which permits access to internal services due to improper channel restriction. The article does not provide specific affected or patched version numbers, CVSS scores, or workarounds.
Read Full Article →

Synology has has fixed critical vulnerabilities in MailPlus Server, a software package used to run private email infrastructure on Synology NAS devices. The security update fixes three flaws: CVE-2026-13136, stemming from faulty authorization checks, may allow remote attackers to read or write arbitrary files and conduct denial-of-service (DoS) attacks CVE-2026-13135, caused by improper restriction of communication channel to intended endpoints, may allow remote attackers to access internal services CVE-2025-15660, arising from the use of a … More → The post Synology issues critical fix for MailPlus Server vulnerabilities appeared first on Help Net Security .

Share this article