Sekurak[verified]@SekurakPatch
The post reports an RCE vulnerability in FreeScout (CVE-2026-27636), details the exploitation method, and advises updating to version 1.8.207 or newer to remediate.
ThreatSynop[verified]@ThreatSynopPatch
The article warns that a newly reported Mail2Shell flaw bypasses the patch for CVE‑2026‑27636 on FreeScout, allowing attackers to overwrite .htaccess and achieve remote code execution via malicious PHP, though it does not confirm ongoing exploitation or provide a PoC.
ThreatSynop[verified]@ThreatSynopDisclosure
SecurityWeek reports a zero‑click RCE in FreeScout (CVE‑2026‑28289) that bypasses a prior patch via a zero‑width space trick, enabling unauthenticated .htaccess uploads and full server takeover on Apache deployments.
mysocAi[verified]@MysocAiDisclosure
The post announces a new RCE vulnerability in FreeScout (CVE-2026-27636) that permits attackers to overwrite config files and execute arbitrary commands, but it does not provide a PoC, exploit code, or patch information.
mysocAi[verified]@MysocAiDisclosure
A new RCE vulnerability (CVE-2026-27636) in FreeScout permits attackers to overwrite configuration files and take over the system; the post provides technical details but no PoC, exploit code, or patch information.
CVETodo[verified]@CveTodoDisclosure
The post announces a file upload vulnerability in FreeScout that allows uploading critical server configuration files such as .htaccess and .user.ini, potentially leading to remote code execution.
CCB Alert@CCBalertPatch
The advisory announces a new patch for FreeScout that addresses CVE‑2026‑27636, an RCE vulnerability, and warns users that they remain vulnerable even after recent updates.
CCB Alert@CCBalertPatch
Two critical vulnerabilities in FreeScout (CVE‑2026‑27636 and CVE‑2026‑27637) enable remote code execution; a patch is available and recommended.