OffSeq | Adversary Tactics for Cyber Resilience[verified]@offseqPatch
FreeScout versions below 1.8.206 allow attackers to generate admin tokens if the APP_KEY leaks, enabling full account takeover; patch immediately.
CVETodo[verified]@CveTodoDisclosure
The post discloses a critical flaw in FreeScout's TokenAuth middleware that generates predictable, static tokens, potentially enabling privilege escalation.
CCB Alert@CCBalertDisclosure
The advisory warns of two critical CVEs in FreeScout that enable remote code execution, and indicates that patches are available.
Autumn Good@autumn_good_35Disclosure
The post lists two new CVEs for FreeScout with brief vulnerability descriptions and links to GitHub advisories, but no PoC, exploit, or patch details are provided.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The text announces a new authentication token bypass vulnerability in FreeScout before version 1.8.206, with no evidence of exploitation or mitigation.
CRAC Learning - Tech@cracbotDisclosure
The post announces a critical vulnerability (CVE-2026-27637) in FreeScout before version 1.8.206, noting its CVSS score but providing no exploit or mitigation details.
PulsePatch.io@pulsepatchioPatch
The post announces a predictable authentication token vulnerability in FreeScout (CVE-2026-27637) and urges users to apply the available patch to mitigate account takeover risk.
CVE@CVEnewDisclosure
The post announces CVE‑2026‑27637, noting that FreeScout’s TokenAuth middleware uses a predictable authentication mechanism prior to version 1.8.206, but provides no PoC, exploit, or patch details.