FreeScout vulnerability enables unauthenticated, zero-click RCE via email (CVE-2026-28289)
ID: c08f0fdf-246a-57c9-bae7-36c247a0558f
STIX ID: report--c08f0fdf-246a-57c9-bae7-36c247a0558f
Feed Name: Help Net Security
A critical RCE vulnerability (CVE-2026-28289) in FreeScout allows attackers to bypass filename validation using a zero-width space, upload malicious .htaccess and webshell files via email to a FreeScout mailbox, and gain unauthenticated remote code execution on Apache servers with AllowOverride All. Researchers advise immediate upgrade to FreeScout v1.8.207 and recommend disabling AllowOverride All; approximately 1,100 publicly exposed FreeScout instances were identified by Shodan, though not all may be vulnerable.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
