logo

Zero-Click FreeScout Bug Enables Remote Code Execution

ID: 7879bdf6-f06c-5eb1-a387-21708d7d940f

STIX ID: report--7879bdf6-f06c-5eb1-a387-21708d7d940f

Feed Name: Infosecurity Magazine (News)

Threat Score
85/100

Date Published: 2026-03-05

Date Updated: 2026-04-22

...
...

**Executive summary:** Ox Security disclosed CVE‑2026‑28289 (Mail2Shell), a maximum‑severity zero‑click RCE in the FreeScout helpdesk platform that bypasses an earlier fix and allows unauthenticated code execution via a crafted email; thousands of instances may be exposed, and customers are urged to upgrade to v1.8.207 and disable AllowOverrideAll in Apache.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.