CVE-2026-2153Active Exploitation(mwielgoszewski / doorman)

LOWCVSS 6.1 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for mwielgoszewski doorman systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability was determined in mwielgoszewski doorman up to 0.6. This issue affects the function is_safe_url of the file doorman/users/views.py. Executing a manipulation of the argument Next can lead to open redirect. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-601

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • doorman

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
doorman

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-06: 1Active Exploitation · 2026-04-06: 1Technical Details · 2026-04-06: 104-06
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
Full discourse1 post
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers are weaponizing open redirects in CVE-2026-1277 and CVE-2026-2153 to bypass email security filters. Phishing campaigns leveraged trusted domains like Google Meet to steal credentials, then moved laterally through cloud environments. Runtime segmentation helps contain post-compromise lateral movement. #Phishing #ZeroTrust :link: Full TRC analysis: https://aviatrix.ai/threat-research-center/phishing-campaigns-exploit-open-redirects-2026

    Post summary

    The analysis reports that CVE‑2026‑1277 and CVE‑2026‑2153 are actively exploited by attackers through open‑redirect payloads in phishing campaigns to bypass email security filters, illustrating real‑world exploitation in cloud environments.

    0001060
    1.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmwielgoszewskidoorman---

Explore more