Synology's recent security update for MailPlus Server is a critical development in the realm of cybersecurity. This fix addresses three severe vulnerabilities that could have far-reaching consequences for users. The first vulnerability, CVE-2026-13136, stems from faulty authorization checks, potentially allowing remote attackers to read or write arbitrary files and conduct denial-of-service (DoS) attacks. The second, CVE-2026-13135, arises from improper restriction of communication channels, enabling remote attackers to access internal services. Lastly, CVE-2025-15660, caused by the use of a cryptographically weak pseudo-random number generator, could allow adjacent attackers to read or write arbitrary files and conduct DoS attacks. These issues are particularly concerning given the widespread use of MailPlus Server, with over 2,100 deployments exposed to the internet. The majority of these deployments are located in Germany, Asia (Korea, China, Taiwan), and the US. This highlights the potential impact of these vulnerabilities on a global scale. What makes this situation even more critical is the lack of available mitigation for the fixed issues. Users running MailPlus Server on NAS devices with DiskStation Manager v7.3, 7.2.2, or 7.2.1 are advised to upgrade to the 4.0.1-31663 version of the software immediately. This update is essential to prevent potential security breaches and data loss. The fact that MailPlus Server is used by both technically inclined users and small-to-medium businesses for self-hosting email on their on-premises hardware further emphasizes the importance of this security update. These businesses may rely on MailPlus Server for privacy, cost control, or compliance reasons, making the protection of their data and systems paramount. In conclusion, Synology's critical fix for MailPlus Server vulnerabilities is a crucial development in cybersecurity. The potential impact of these vulnerabilities on a global scale, coupled with the lack of available mitigation, underscores the urgency of this update. Users are advised to act promptly to ensure the security and integrity of their systems and data.