CVE-2026-28289
CVSS 10 CRITICAL: freeScout is a free help desk and shared inbox built with PHP's Laravel framework. EPSS 31% (98th percentile).
Vulnerabilities · 194 days ago
Ox Security disclosed a patch-bypass vulnerability in FreeScout that allows zero-click remote code execution by saving a crafted .htaccess file (CVE-2026-28289), bypassing a prior fix for CVE-2026-27636. A zero-width space causes a TOCTOU filename-sanitization bypass, enabling RCE. Update FreeScout and block or inspect file uploads for dotfiles and emailed attachments.
CVSS 10 CRITICAL: freeScout is a free help desk and shared inbox built with PHP's Laravel framework. EPSS 31% (98th percentile).
CVSS 8.8 HIGH: freeScout is a free help desk and shared inbox built with PHP's Laravel framework. EPSS 2% (79th percentile).
4 sources covering this story
An authenticated RCE vulnerability (CVE-2026-28289) in FreeScout can be triggered by sending a specially crafted email to a FreeScout mailbox.
Zero-Click FreeScout Bug Enables Remote Code Execution
Ox Security warns that Mail2Shell could enable threat actors to hijack FreeScout systems without user interaction
Mail2Shell zero-click attack lets hackers hijack FreeScout mail servers
A maximum severity vulnerability in the FreeScout helpdesk platform allows hackers to achieve remote code execution without any user interaction or authentication.
Critical FreeScout Vulnerability Leads to Full Server Compromise
A patch bypass for an authenticated code execution bug, the flaw leads to zero-click remote code execution attacks.
Part of the PlainSec briefing for 2026-03-15