CVE-2026-28289
CVSS 10 CRITICAL: freeScout is a free help desk and shared inbox built with PHP's Laravel framework. EPSS 31% (98th percentile).
Vulnerabilities & Exploits · Zero-Day Exploit
The bug bypasses a prior fix for CVE-2026-27636 by using a zero-width space to save a .htaccess dotfile, creating a TOCTOU filename-sanitization bypass and enabling unauthenticated RCE.
4 sources · Mar 5
CVSS 10 CRITICAL: freeScout is a free help desk and shared inbox built with PHP's Laravel framework. EPSS 31% (98th percentile).
CVSS 8.8 HIGH: freeScout is a free help desk and shared inbox built with PHP's Laravel framework. EPSS 2% (79th percentile).
Help Net Security
FreeScout vulnerability enables unauthenticated, zero-click RCE via email (CVE-2026-28289) - Help Net Security
An authenticated RCE vulnerability (CVE-2026-28289) in FreeScout can be triggered by sending a specially crafted email to a FreeScout mailbox.
originalInfosecurity Magazine
Zero-Click FreeScout Bug Enables Remote Code Execution
Ox Security warns that Mail2Shell could enable threat actors to hijack FreeScout systems without user interaction
originalBleepingComputer
Mail2Shell zero-click attack lets hackers hijack FreeScout mail servers
A maximum severity vulnerability in the FreeScout helpdesk platform allows hackers to achieve remote code execution without any user interaction or authentication.
originalPart of the PlainSec briefing for 2026-03-05
Every edition of this story: Critical FreeScout Flaw Enables Zero-Click Server Compromise