CVE-2026-28289
CVSS 10 CRITICAL: freeScout is a free help desk and shared inbox built with PHP's Laravel framework. EPSS 3% (84º percentile).
Vulnerabilità ed exploit · Exploit zero-day
FreeScout contiene una vulnerabilità critica (CVE-2026-28289) che permette RCE senza autenticazione e senza interazione dell'utente. La falla bypassa la correzione per CVE-2026-27636 usando un zero-width space (U+200B) che genera un TOCTOU nella sanitizzazione dei nomi file e consente di salvare un .htaccess dotfile. Un allegato email maligno può essere scritto sotto /storage/attachment e richiamato via web per eseguire comandi sul server.
4 fonti · 5 mar
CVSS 10 CRITICAL: freeScout is a free help desk and shared inbox built with PHP's Laravel framework. EPSS 3% (84º percentile).
CVSS 8.8 HIGH: freeScout is a free help desk and shared inbox built with PHP's Laravel framework. EPSS 2% (81º percentile).
Help Net Security
FreeScout vulnerability enables unauthenticated, zero-click RCE via email (CVE-2026-28289) - Help Net Security
An authenticated RCE vulnerability (CVE-2026-28289) in FreeScout can be triggered by sending a specially crafted email to a FreeScout mailbox.
originaleInfosecurity Magazine
Zero-Click FreeScout Bug Enables Remote Code Execution
Ox Security warns that Mail2Shell could enable threat actors to hijack FreeScout systems without user interaction
originaleBleepingComputer
Mail2Shell zero-click attack lets hackers hijack FreeScout mail servers
A maximum severity vulnerability in the FreeScout helpdesk platform allows hackers to achieve remote code execution without any user interaction or authentication.
originalePart of the PlainSec briefing for 2026-03-06
Every edition of this story: FreeScout: RCE Zero-Click Permette Compromissione Completa del Server