CVE-2026-27636Disclosure(freescout / freescout)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch freescout freescout systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's file upload restriction list in `app/Misc/Helper.php` does not include `.htaccess` or `.user.ini` files. On Apache servers with `AllowOverride All` (a common configuration), an authenticated user can upload a `.htaccess` file to redefine how files are processed, enabling Remote Code Execution. This vulnerability can be exploited on its own or in combination with CVE-2026-27637. Version 1.8.206 fixes both vulnerabilities.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freescout

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 18 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 14 signals
  • Disclosure: 8 classified signals
  • General: 3 classified signals
  • Peaked 5d ago at 7 mentions (2026-02-25); latest day: 1
  • 18 total mentions across 6 days

Affected systems

Vendors
Products
freescout

Deep dive

Activity timeline18 mentions / 6d
02457Mentions · 2026-02-25: 7Mentions · 2026-02-26: 3Mentions · 2026-03-02: 1Mentions · 2026-03-03: 3Mentions · 2026-03-04: 3Mentions · 2026-03-06: 1PoC Mentioned / Linked · 2026-02-25: 1PoC Mentioned / Linked · 2026-02-26: 1Patch / Workaround · 2026-02-25: 2Patch / Workaround · 2026-03-03: 1Patch / Workaround · 2026-03-04: 1Patch / Workaround · 2026-03-06: 1Technical Details · 2026-02-25: 5Technical Details · 2026-02-26: 2Technical Details · 2026-03-02: 1Technical Details · 2026-03-03: 2Technical Details · 2026-03-04: 3Technical Details · 2026-03-06: 102-2502-2603-0203-0303-0403-06
Signal classification4 categories
Disclosure
844.4%
Patch
527.8%
General
316.7%
PoC
211.1%
Referenced assets17 URLs
Classification over time
DateTotalLabels
2026-02-257
Disclosure2General2Patch2PoC1
2026-02-263
Disclosure2PoC1
2026-03-021
Disclosure1
2026-03-033
Disclosure1General1Patch1
2026-03-043
Disclosure2Patch1
2026-03-061
Patch1
Full discourse18 posts
  • Sekurak@Sekurak
    Patch

    ⚠️ W aplikacji FreeScout wykryto podatność RCE (CVE-2026-27636) umożliwiającą wykonanie dowolnego kodu na serwerze. ⚠️ Atak polegał na wgraniu pliku .htaccess, który wymuszał interpretowanie plików .txt jako kodu PHP. Niezbędne było posiadanie konta na podatnej instancji FreeScout. ⚠️ Pierwsza poprawka (blokowanie dotfiles) została ominięta poprzez użycie znaku zero-width space w nazwie pliku. Ostateczne rozwiązanie polega na zmianie kolejności walidacji i sanityzacji nazw plików. ⚠️ Administratorzy powinni zaktualizować FreeScout do wersji 1.8.207 lub nowszej. Czytaj więcej: https://sekurak.pl/problemy-z-walidacja-nazw-plikow-umozliwialy-rce-i-patch-bypass-w-narzedziu-freescout/

    Post summary

    The post reports an RCE vulnerability in FreeScout (CVE-2026-27636), details the exploitation method, and advises updating to version 1.8.207 or newer to remediate.

    4401944.3K
    42.5K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: New patch available for #FreeScout helpdesk. This version fixes a patch bypass for CVE-2026-27636, a remote code execution vulnerability. Even if you updated last week (v1.8.206), you are vulnerable! https://ccb.belgium.be/advisories/warning-critical-vulnerabilities-freescout-could-be-exploited-achieve-remote-code #Patch #Patch #Patch

    Post summary

    The advisory announces a new patch for FreeScout that addresses CVE‑2026‑27636, an RCE vulnerability, and warns users that they remain vulnerable even after recent updates.

    02032534
    7.2K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Two critical vulnerabilities in #FreeScout help desk. #CVE-2026-27636 and #CVE-2026-27637 can be exploited independently or chained together to achieve remote code execution #RCE! https://ccb.belgium.be/advisories/warning-critical-vulnerabilities-freescout-could-be-exploited-achieve-remote-code #Patch #Patch #Patch

    Post summary

    Two critical vulnerabilities in FreeScout (CVE‑2026‑27636 and CVE‑2026‑27637) enable remote code execution; a patch is available and recommended.

    02010273
    7.2K followersView on X
  • Autumn Good@autumn_good_35
    General

    🚨🚨🚨 FreeScout CVE-2026-27636 Missing .htaccess in Restricted File Extensions Allows Remote Code Execution on Apache https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-mw88-x7j3-74vc CVE-2026-27637 Predictable Authentication Token Enables Account Takeover https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-6gcm-v8xf-j9v9

    Post summary

    The post lists two FreeScout CVE advisories with brief titles and GitHub links, but offers no PoC, exploit code, active exploitation evidence, or patch details.

    01010432
    6.7K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 ‘Mail2Shell’ Patch Bypass Puts FreeScout Servers Back at Risk of Remote Code Execution A newly reported “Mail2Shell” flaw lets attackers bypass FreeScout’s earlier fix for CVE-2026-27636 by abusing a zero-width space to overwrite .htaccess and execute malicious PHP files. This matters because exposed FreeScout instances can be pushed from authenticated compromise to potential unauthenticated RCE through inbound email processing. 🎯 Target: Global/Publicly Exposed FreeScout Instances #️⃣ Category: #Vulnerability #BlueTeam #TargetedAttacks 🔗 URL: https://www.scworld.com/news/mail2shell-freescout-patch-bypass-exploit-leads-to-rce

    Post summary

    The article warns that a newly reported Mail2Shell flaw bypasses the patch for CVE‑2026‑27636 on FreeScout, allowing attackers to overwrite .htaccess and achieve remote code execution via malicious PHP, though it does not confirm ongoing exploitation or provide a PoC.

    0001051
    258 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-28289 - Critical FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier allows any authenticate... https://www.thehackerwire.com/vulnerability/CVE-2026-28289/ https://t.co/aDOfA2i0da

    Post summary

    The post announces a critical patch bypass vulnerability in FreeScout that permits unauthenticated access, but it does not provide a PoC, exploit code, or evidence of active exploitation.

    1000060
    121 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-28289 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier al… https://www.cve.org/CVERecord?id=CVE-2026-28289 ----- Traducción: CVE-2026-28289 Fre… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-28289, noting it is a patch bypass vulnerability affecting FreeScout 1.8.206 and earlier, but provides no PoC, exploit, or patch details.

    1000060
    55 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-28289 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier al… https://www.cve.org/CVERecord?id=CVE-2026-28289

    Post summary

    The snippet references CVE-2026-28289 and mentions a patch bypass issue related to CVE-2026-27636 in older FreeScout versions, but offers no detailed technical information or actionable guidance.

    10000216
    56.6K followersView on X
  • Moshe Siman Tov Bustan@MosheTov
    PoC

    FreeScout Exploit POC Walkthrough CVE-2026-27636 https://youtu.be/scaIGkDc29g

    Post summary

    A YouTube walkthrough demonstrates a proof‑of‑concept exploit for CVE‑2026‑27636 in FreeScout.

    00010177
    77 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27636 Remote Code Execution in FreeScout via Malicious .htaccess File Upload https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27636

    Post summary

    A new RCE vulnerability (CVE-2026-27636) in FreeScout allows attackers to upload malicious .htaccess files, potentially leading to remote code execution.

    0001046
    4.0K followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 Critical FreeScout RCE (CVE-2026-28289) Enables Zero-Click Full Server Compromise via .htaccess Patch Bypass SecurityWeek reports Ox Security found CVE-2026-28289 (CVSS 10) in FreeScout: a zero-width space trick bypasses the prior CVE-2026-27636 fix, allowing a crafted “.htaccess” upload that leads to unauthenticated, zero-click RCE and full server takeover on Apache deployments. This matters because helpdesk platforms often store sensitive customer emails/tickets and sit on internal networks, making exploitation a high-impact pivot point. 🎯 Target: Global/IT & Customer Support (FreeScout Deployments) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.securityweek.com/critical-freescout-vulnerability-leads-to-full-server-compromise/

    Post summary

    SecurityWeek reports a zero‑click RCE in FreeScout (CVE‑2026‑28289) that bypasses a prior patch via a zero‑width space trick, enabling unauthenticated .htaccess uploads and full server takeover on Apache deployments.

    0000055
    262 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-27636 (CVSS:8.8, HIGH) is Analyzed. FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's..https://nvd.nist.gov/vuln/detail/CVE-2026-27636 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE-2026-27636, noting its high severity and affected FreeScout version, but provides no further details or mitigation.

    0000031
    173 followersView on X
  • mysocAi@MysocAi
    Disclosure

    [HIGH] FreeScout RCE Vulnerability Allows Full Server Takeover CVE-2026-27636 enables attackers to overwrite config files and execute arbitrary commands. CVE: CVE-2026-27636 • APT: Unknown • Status: ACTIVE Critic… https://www.cybersecbrief.com/news/cybersec/cybersec-2026-02-26

    Post summary

    The post announces a new RCE vulnerability in FreeScout (CVE-2026-27636) that permits attackers to overwrite config files and execute arbitrary commands, but it does not provide a PoC, exploit code, or patch information.

    000007
    3 followersView on X
  • mysocAi@MysocAi
    Disclosure

    [HIGH] FreeScout RCE Vulnerability Discovered CVE-2026-27636 allows full system takeover via configuration file overwrite. CVE: CVE-2026-27636 • APT: Unknown • Status: ACTIVE Web applications vulnerable. #mysocA… https://www.cybersecbrief.com/news/cybersec/cybersec-2026-02-26

    Post summary

    A new RCE vulnerability (CVE-2026-27636) in FreeScout permits attackers to overwrite configuration files and take over the system; the post provides technical details but no PoC, exploit code, or patch information.

    000007
    3 followersView on X
  • Moshe Siman Tov Bustan@MosheTov
    PoC

    𝐈𝐟 𝐲𝐨𝐮 𝐡𝐚𝐯𝐞 𝐚 𝐡𝐚𝐫𝐝𝐜𝐨𝐝𝐞𝐝 "𝐛𝐥𝐚𝐜𝐤𝐥𝐢𝐬𝐭" 𝐢𝐧 𝐲𝐨𝐮𝐫 𝐜𝐨𝐝𝐞, 𝐲𝐨𝐮 𝐡𝐚𝐯𝐞 𝐚 𝐬𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐛𝐮𝐠. Read about the 𝐥𝐚𝐭𝐞𝐬𝐭 𝐅𝐫𝐞𝐞𝐒𝐜𝐨𝐮𝐭'𝐬 𝐯𝐮𝐥𝐧𝐞𝐫𝐚𝐛𝐢𝐥𝐢𝐭𝐲 (CVE-2026-27636) - with an exploit POC https://www.ox.security/blog/freescout-rce-cve-2026-27636/ https://t.co/vKlM5l9UmX

    Post summary

    The post announces CVE-2026-27636 for Freescout and indicates that an exploit proof‑of‑concept is available via the provided link.

    00000102
    77 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-27636 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's file upload restriction list in `app/Misc/Hel… https://www.cve.org/CVERecord?id=CVE-2026-27636

    Post summary

    The text references CVE‑2026‑27636 for FreeScout but offers no substantive details, PoC, exploit, or mitigation information.

    00000104
    56.6K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-27636: HIGH] FreeScout's security vulnerability pre-version 1.8.206 exposes risks for Remote Code Execution due to inadequate file upload restrictions. Update to version 1.8.206 for fixes.#cve,CVE-2026-27636,#cybersecurity https://cvefind.com/CVE-2026-27636

    Post summary

    The advisory highlights a high‑severity RCE vulnerability in FreeScout versions prior to 1.8.206 and recommends updating to 1.8.206 to mitigate the issue.

    0000047
    584 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-27636** pertains to a file upload vulnerability in **FreeScout**, a PHP-based help desk and shared inbox application built on the Laravel framework. Prior to version **1.8.206**, the application’s file upload restrictions did not include critical server configuration files such as `.htaccess` and `.user.ini`. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #Apache https://cvetodo.com/cve/CVE-2026-27636

    Post summary

    The post announces a file upload vulnerability in FreeScout that allows uploading critical server configuration files such as .htaccess and .user.ini, potentially leading to remote code execution.

    0000049
    20 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfreescoutfreescout---

Explore more