Mail2Shell Zero-Click Attack lets Hackers Hijack FreeScout Mail Servers
ID: 8334a96d-589e-5b56-a448-590fe198ebb4
STIX ID: report--8334a96d-589e-5b56-a448-590fe198ebb4
Feed Name: cybersecurityNews.com
Threat Score
Researchers disclosed a critical zero-click escalation called "Mail2Shell" (CVE-2026-28289) in the FreeScout helpdesk application that bypasses a prior patch by using a zero-width space (U+200B) in filenames to upload malicious dotfiles, enabling unauthenticated remote code execution and full server takeover; administrators are urged to update to FreeScout 1.8.207 immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
