Critical FreeScout Vulnerability Leads to Full Server Compromise

Ox Security disclosed a patch-bypass vulnerability in FreeScout that allows zero-click remote code execution by saving a crafted .htaccess file (CVE-2026-28289), bypassing a prior fix for CVE-2026-27636. A zero-width space causes a TOCTOU filename-sanitization bypass, enabling RCE. Update FreeScout and block or inspect file uploads for dotfiles and emailed attachments.

Part of the PlainSec briefing for 2026-03-15

Sources