logo

Mail2Shell zero-click attack lets hackers hijack FreeScout mail servers

ID: 73fe1e52-3f57-58a9-b967-89cbefc4c91b

STIX ID: report--73fe1e52-3f57-58a9-b967-89cbefc4c91b

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-03-04

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A critical zero-click remote code execution vulnerability (CVE-2026-28289) in FreeScout lets attackers bypass filename validation by prefixing attachments with a zero-width space, enabling unauthenticated upload of malicious files (such as .htaccess) and potential full server compromise; the flaw affects versions up to 1.8.206, was patched in 1.8.207, and immediate patching plus configuration changes are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.