Synology just dropped an urgent security advisory for its DSM platform: the MailPlus Server email suite needs an immediate patch. If you’re still running an older version, you could be exposed to unauthorized file access, internal service exposure, and even denial-of-service (DoS) attacks. In worst-case scenarios, attackers may leverage the flaws to read/write arbitrary files remotely and then knock your mail service offline. The bulletin covers three related vulnerabilities. The most severe is CVE-2026-13136 with a CVSS score of 10.0. The root issue is broken authorization validation—meaning crafted remote requests may allow arbitrary file read/write, followed by DoS. Next is CVE-2025-15660 (CVSS 9.6), tied to insufficient strength in the crypto random number generator. While the cause differs, the outcome is still “high misuse potential,” including support for file read/write abuse and service disruption. Synology recommends upgrading fast (examples include 4.0.1-21663 / 4.0.1-31663). And the scary part: scanner data still shows 2,100+ MailPlus Server instances publicly reachable online—so the attack surface remains. Check versions today, patch today. #Synology #DSM #MailPlus #CyberSecurity #ZeroDays #CVE
Want to learn more? Visit Explore the world, stay updated on travel insights and international affairs, and discover authentic stories from real life
评论
发表评论