Mail2Shell zero-click attack lets hackers hijack FreeScout mail servers
ID: 73fe1e52-3f57-58a9-b967-89cbefc4c91b
STIX ID: report--73fe1e52-3f57-58a9-b967-89cbefc4c91b
Feed Name: Bleeping Computer
Threat Score
A critical zero-click remote code execution vulnerability (CVE-2026-28289) in FreeScout lets attackers bypass filename validation by prefixing attachments with a zero-width space, enabling unauthenticated upload of malicious files (such as .htaccess) and potential full server compromise; the flaw affects versions up to 1.8.206, was patched in 1.8.207, and immediate patching plus configuration changes are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
