logo

CVSS 10.0 Unauthenticated Remote Code Execution in FreeScout (Public Proof-of-Concept Disclosed)

ID: 52864212-f4ca-5637-8034-d79076b1c5d9

STIX ID: report--52864212-f4ca-5637-8034-d79076b1c5d9

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-03-05

Date Updated: 2026-04-23

Author: Ddos

...
...

Security researchers disclosed CVE-2026-28289, a CVSS 10.0 TOCTOU vulnerability in FreeScout 1.8.206 where an attacker can prefix filenames with a zero-width space to bypass dot-file checks, upload a malicious .htaccess, and achieve unauthenticated RCE and full server compromise; administrators are urged to upgrade to 1.8.207 immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.