CVE-2026-21859Active Exploitation(axllent / mailpit)

LOWCVSS 5.3 · MEDIUM

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for axllent mailpit systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Mailpit is an email testing tool and API for developers. Versions 1.28.0 and below have a Server-Side Request Forgery (SSRF) vulnerability in the /proxy endpoint, allowing attackers to make requests to internal network resources. The /proxy endpoint validates http:// and https:// schemes, but it does not block internal IP addresses, enabling attackers to access internal services and APIs. This vulnerability is limited to HTTP GET requests with minimal headers. The issue is fixed in version 1.28.1.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mailpit

Threat summary

  • Active exploitation appears in 2 classified signals
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Technical details provided in 2 signals
  • Peaked at 2 mentions on most recent observed day (2026-10-09)
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
mailpit

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-02: 1Mentions · 2026-03-27: 1Mentions · 2026-10-09: 2Active Exploitation · 2026-03-02: 1Active Exploitation · 2026-03-27: 1Technical Details · 2026-03-02: 1Technical Details · 2026-03-27: 103-0203-2710-09
Signal classification1 categories
Active Exploitation
2100.0%
Referenced assets2 URLs
Full discourse4 posts
  • ♫NØX♥H♪@_Why_Noot

    NØX Echo Lineage Signal: CVE-2026-21859 Entity: mailpit Lineage: Public vulnerability → Observed exploitation Relationship: - mailpit → CVE-2026-21859 → Evidence → Operational Risk Current State: DISCLOSED, ACTIVE_EXPLOITATION Watch: - New infrastructure

    1000028
    8 followersView on X
  • Divert@Divert_Security
    Active Exploitation

    Another pre-disclosure exploit attempt: CVE-2026-21859 was a Mailpit SSRF disclosed on 1/7/2026. We detected one on 1/4/2026. https://t.co/7AZlQOyvbc

    Post summary

    The tweet reports that CVE-2026-21859, a Mailpit SSRF, was actively exploited on 1/4/2026, with the detection noted in a linked tweet but no patch or PoC provided.

    0001048
    8 followersView on X
  • CrowdSec@Crowd_Security
    Active Exploitation

    🚨 This week’s CrowdSec Threat Alert: CVE-2026-21859, a critical SSRF vulnerability in Mailpit, is being actively exploited to map internal networks and access sensitive infrastructure. See how the exploit works, what targeted reconnaissance reveals, and why exposed dev tools can become high-impact entry points in our latest article 👉 https://www.crowdsec.net/vulntracking-report/cve-2026-21859 #CVE #CVE202621859 #threatalert #cybersecurity

    Post summary

    CVE-2026-21859 is a critical SSRF flaw in Mailpit that is currently being exploited in the wild to map internal networks and access sensitive infrastructure, as reported by CrowdSec.

    00010343
    19.6K followersView on X
  • ♫Why♥Not♪@Python_s_

    NØØT Security Alerts Classification: Critical CVE: CVE-2026-21859 Product: axllent / mailpit Summary: VulnCheck reports real-world exploitation activity affecting axllent / mailpit. Evidence: Active exploitation reported; Live exploitation observed by VulnCheck canaries Impact: The vulnerability can materially affect exposed systems; verify vendor-specific impact and affected versions. Action: Prioritize vendor remediation, identify exposed affected systems, and investigate for evidence of exploitation when applicable. Date: 11 Feb 2026 Source: https://vulncheck.com/ #NØØT #CyberSecurity #InfoSec #ThreatIntelligence #CyberThreats #CVE #CyberDefense #mailpit #CVE_2026_21859 #ActiveExploitation #Exploit

    0000027
    229 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appaxllentmailpit---

Explore more