CVSS 10.0 Unauthenticated Remote Code Execution in FreeScout (Public Proof-of-Concept Disclosed)
ID: 52864212-f4ca-5637-8034-d79076b1c5d9
STIX ID: report--52864212-f4ca-5637-8034-d79076b1c5d9
Feed Name: securityonline.info
Threat Score
Security researchers disclosed CVE-2026-28289, a CVSS 10.0 TOCTOU vulnerability in FreeScout 1.8.206 where an attacker can prefix filenames with a zero-width space to bypass dot-file checks, upload a malicious .htaccess, and achieve unauthenticated RCE and full server compromise; administrators are urged to upgrade to 1.8.207 immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
