If you stopped at Click2Shell / 7.1.1, you are not done.
CVE-2026-87902 is unauth LFI in core template resolution. Patchstack saw probes the same day.
Update to 7.1.2 or your backport. Hunt logs for odd pagename + page_id.
Already patched? Drop a ✅. Agency life? Pass it to your clients.