Synology has released a security update for the Synology MailPlus Server package in DSM to address multiple vulnerabilities : CVE-2026-13136 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks. CVE-2025-15660 (ZDI-CAN-28554) allows adjacent attackers to read or write arbitrary files and conduct denial-of-service attacks. CVE-2026-13135 (ZDI-CAN-28485) allows remote attackers to access internal services. Please refer to the 'Affected Products' table for the corresponding updates.
Continue reading...
- - -
Synology Product Security Advisory: check the list
Source: synology.com
Continue reading...
- - -
Synology Product Security Advisory: check the list
Source: synology.com