CompuChris[verified]@compuchrisDisclosure
The tweet announces CVE‑2026‑33656, a critical (CVSS 9.1) authenticated RCE in EspoCRM versions ≤ 9.3.3 via path traversal and the formula engine, but does not mention active exploitation, a PoC, an exploit tool, or mitigation information.
/r/netsec@_r_netsecPoC
The post announces CVE‑2026‑33656 in EspoCRM, detailing an ACL gap and path traversal that enable authenticated RCE, and links to a full write‑up with a proof‑of‑concept.
CVE@CVEnewGeneral
The post identifies CVE-2026-33656 in EspoCRM but offers no additional details about the vulnerability, its exploitation, or remediation.
CCB Alert@CCBalertDisclosure
This tweet announces a severe CVE‑2026‑33656 in EspoCRM that enables remote code execution for admin users, but it lacks information on patches, PoC, or active exploitation.
0day Signal@0dayPublishingDisclosure
The post announces a new EspoCRM path traversal vulnerability (CVE‑2026‑33656), describing how an admin‑level traversal bypasses sanitization. No evidence of active exploitation or available patches is mentioned.
Gray Hats@the_yellow_fallPoC
EspoCRM 9.3.3’s Formula Engine contains a critical RCE (CVE‑2026‑33656) that can be exploited in just six requests, with a PoC publicly referenced. No evidence of active exploitation or patched mitigations is provided.
CrowdCyber 🌐@CrowdCyber_ComPoC
The post announces CVE-2026-33656, detailing an authenticated RCE via a formula‑engine ACL gap and path traversal in EspoCRM ≤9.3.3, and shares a full write‑up and PoC.
Security Harvester@secharvesterxPoC
EspoCRM ≤ 9.3.3 is vulnerable to authenticated RCE via a formula engine ACL gap coupled with path traversal. A complete write‑up and PoC are available.