Synology just dropped an urgent security advisory for its DSM platform: the MailPlus Server email suite needs an immediate patch. If you’re still running an older version, you could be exposed to unauthorized file access, internal service exposure, and even denial-of-service (DoS) attacks. In worst-case scenarios, attackers may leverage the flaws to read/write arbitrary files remotely and then knock your mail service offline. The bulletin covers three related vulnerabilities. The most severe is CVE-2026-13136 with a CVSS score of 10.0. The root issue is broken authorization validation—meaning crafted remote requests may allow arbitrary file read/write, followed by DoS. Next is CVE-2025-15660 (CVSS 9.6), tied to insufficient strength in the crypto random number generator. While the cause differs, the outcome is still “high misuse potential,” including support for file read/write abuse and service disruption. Synology recommends upgrading fast (examples include 4.0.1-21663 / 4.0.1-3...