
CVE-2026-40567 FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can inject arbitrary HTML into outgoing emails gen… https://www.cve.org/CVERecord?id=CVE-2026-40567
Post summary
The statement announces a code injection flaw (unauthenticated HTML injection into outgoing emails) in FreeScout versions before 1.8.213, but provides no PoC, exploit, patch, or evidence of active exploitation.

