Zero-Click FreeScout Bug Enables Remote Code Execution
ID: 7879bdf6-f06c-5eb1-a387-21708d7d940f
STIX ID: report--7879bdf6-f06c-5eb1-a387-21708d7d940f
Feed Name: Infosecurity Magazine (News)
Threat Score
**Executive summary:** Ox Security disclosed CVE‑2026‑28289 (Mail2Shell), a maximum‑severity zero‑click RCE in the FreeScout helpdesk platform that bypasses an earlier fix and allows unauthenticated code execution via a crafted email; thousands of instances may be exposed, and customers are urged to upgrade to v1.8.207 and disable AllowOverrideAll in Apache.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
