Metasploit Project[verified]@metasploitExploit
Rapid7’s Metasploit Framework releases five new modules, featuring RCE exploits for FreeScout (CVE‑2026‑28289) and Grav CMS (CVE‑2025‑50286), alongside a generic HTTP command execution module and a new Windows persistence technique.
キタきつね[verified]@foxbookDisclosure
A new unauthenticated, zero‑click remote code execution vulnerability (CVE‑2026‑28289) for FreeScout has been disclosed, but no exploit code, patch, or active exploitation evidence is mentioned.
The Cyber Security Hub™[verified]@TheCyberSecHubDisclosure
The tweet announces that FreeScout has a new unauthenticated, zero‑click remote code execution vulnerability (CVE‑2026‑28289) that can be triggered via email, without providing a PoC, patch advice, or evidence of active exploitation.
maru[verified]@maru1151157Patch
CVE-2026-28289 is a CVSS 10 RCE in FreeScout caused by a TOCTOU bug; the issue is fixed in version 1.8.207, with a link to the advisory provided.
Shah Sheikh[verified]@shah_sheikhDisclosure
A newly discovered CVE‑2026‑28289 in FreeScout permits unauthenticated, zero‑click remote code execution via email, with no PoC, exploit, or patch information provided.
Gray Hats@the_yellow_fallPoC
The tweet announces a critical CVE‑2026‑28289 and provides links to a potential proof‑of‑concept demonstrating a zero‑click RCE via a single email that leverages a zero‑width space bypass.
Gray Hats@the_yellow_fallPoC
A critical remote‑code‑execution flaw (CVE‑2026‑28289) in FreeScout with a CVSS score of 10.0 has been publicly disclosed, including a PoC that demonstrates server takeover via an invisible character exploit. No active exploitation or patch information is mentioned.
Help Net Security@helpnetsecurityDisclosure
The tweet announces the discovery of a CVE-2026-28289 vulnerability in FreeScout that allows unauthenticated, zero-click remote code execution via email, with a reference to a report that likely includes a PoC.