Vulnerabilities · 194 days ago

Critical FreeScout Vulnerability Leads to Full Server Compromise

Ox Security disclosed a patch-bypass vulnerability in FreeScout that allows zero-click remote code execution by saving a crafted .htaccess file (CVE-2026-28289), bypassing a prior fix for CVE-2026-27636. A zero-width space causes a TOCTOU filename-sanitization bypass, enabling RCE. Update FreeScout and block or inspect file uploads for dotfiles and emailed attachments.

CVE-2026-28289

NVD KEV

CVSS 10 CRITICAL: freeScout is a free help desk and shared inbox built with PHP's Laravel framework. EPSS 31% (98th percentile).

CVE-2026-27636

NVD KEV

CVSS 8.8 HIGH: freeScout is a free help desk and shared inbox built with PHP's Laravel framework. EPSS 2% (79th percentile).

Timeline

Sources

4 sources covering this story

Entities

Part of the PlainSec briefing for 2026-03-15

Editions

Related stories