CVE-2026-28289Disclosure(freescout / freescout)

HIGHCVSS 8.1 · HIGH

Exploitation observed; activity peaked at 14 mentions and remains active

Immediate actions

  • Patch freescout freescout systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier allows any authenticated user with file upload permissions to achieve Remote Code Execution (RCE) on the server by uploading a malicious .htaccess file using a zero-width space character prefix to bypass the security check. The vulnerability exists in the sanitizeUploadedFileName() function in app/Http/Helper.php. The function contains a Time-of-Check to Time-of-Use (TOCTOU) flaw where the dot-prefix check occurs before sanitization removes invisible characters. This vulnerability is fixed in 1.8.207.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freescout

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 39 mentions across 8 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 12 signals
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 30 signals
  • Disclosure: 20 classified signals
  • General: 7 classified signals
  • Peaked 5d ago at 14 mentions (2026-03-05); latest day: 1
  • 39 total mentions across 8 days

Affected systems

Vendors
Products
freescout

Deep dive

Activity timeline39 mentions / 8d
0471114Mentions · 2026-03-03: 6Mentions · 2026-03-04: 11Mentions · 2026-03-05: 14Mentions · 2026-03-06: 3Mentions · 2026-03-12: 1Mentions · 2026-03-16: 2Mentions · 2026-04-03: 1Mentions · 2026-04-08: 1PoC Mentioned / Linked · 2026-03-03: 2PoC Mentioned / Linked · 2026-03-04: 3PoC Mentioned / Linked · 2026-03-05: 4PoC Mentioned / Linked · 2026-03-06: 1PoC Mentioned / Linked · 2026-03-16: 1PoC Mentioned / Linked · 2026-04-03: 1Exploit Tool / Code · 2026-03-05: 1Exploit Tool / Code · 2026-04-03: 1Active Exploitation · 2026-03-04: 1Patch / Workaround · 2026-03-03: 1Patch / Workaround · 2026-03-04: 3Patch / Workaround · 2026-03-05: 2Patch / Workaround · 2026-03-12: 1Technical Details · 2026-03-03: 3Technical Details · 2026-03-04: 8Technical Details · 2026-03-05: 13Technical Details · 2026-03-06: 3Technical Details · 2026-03-12: 1Technical Details · 2026-03-16: 1Technical Details · 2026-04-03: 103-0303-0403-0503-0603-1203-1604-0304-08
Signal classification5 categories
Disclosure
2051.3%
General
717.9%
Patch
615.4%
PoC
410.3%
Exploit
25.1%
Referenced assets25 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-036
Disclosure2General2Patch1PoC1
2026-03-0411
Disclosure6Exploit1General2Patch2
2026-03-0514
Disclosure9General1Patch2PoC2
2026-03-063
Disclosure2PoC1
2026-03-121
Patch1
2026-03-162
Disclosure1General1
2026-04-031
Exploit1
2026-04-081
General1
Full discourse20 posts
  • Metasploit Project@metasploit
    Exploit

    Metasploit Framework is here with 5 new modules! Exploits for FreeScout (CVE-2026-28289) and Grav CMS (CVE-2025-50286) RCEs, plus a generic HTTP command execution module and a new Windows persistence technique. We also have a slew of bug fixes and enhancements including SOCKS proxy performance improvements #Metasploit https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-04-03-2026/1

    Post summary

    Rapid7’s Metasploit Framework releases five new modules, featuring RCE exploits for FreeScout (CVE‑2026‑28289) and Grav CMS (CVE‑2025‑50286), alongside a generic HTTP command execution module and a new Windows persistence technique.

    11003586.3K
    253.3K followersView on X
  • Gray Hats@the_yellow_fall
    PoC

    Critical CVE-2026-28289 allows zero-click RCE on FreeScout via a single email. Learn how the "zero-width space" bypasses security to hijack helpdesk servers. https://meterpreter.org/the-phantom-character-how-a-single-email-can-seize-full-control-of-your-freescout-helpdesk/ https://t.co/PI9IKuQoGF

    Post summary

    The tweet announces a critical CVE‑2026‑28289 and provides links to a potential proof‑of‑concept demonstrating a zero‑click RCE via a single email that leverages a zero‑width space bypass.

    040104767
    10.6K followersView on X
  • Gray Hats@the_yellow_fall
    PoC

    A critical 10.0 CVSS unauthenticated remote code execution flaw (CVE-2026-28289) in FreeScout allows full server takeover via an invisible character exploit. #FreeScout #CyberSecurity #CVE202628289 #RCE #InfoSec #Vulnerability #PatchAlert #HelpDesk https://securityonline.info/cvss-10-0-unauthenticated-remote-code-execution-in-freescout-public-proof-of-concept-disclosed/

    Post summary

    A critical remote‑code‑execution flaw (CVE‑2026‑28289) in FreeScout with a CVSS score of 10.0 has been publicly disclosed, including a PoC that demonstrates server takeover via an invisible character exploit. No active exploitation or patch information is mentioned.

    14083720
    10.5K followersView on X
  • Help Net Security@helpnetsecurity
    Disclosure

    FreeScout vulnerability enables unauthenticated, zero-click RCE via email (CVE-2026-28289) - https://www.helpnetsecurity.com/2026/03/05/freescout-vulnerability-cve-2026-28289/ - @OX__Security #CVE #opensource #PoC #SecurityUpdate #Cybersecurity #CybersecurityNews https://t.co/YGxy2aObf4

    Post summary

    The tweet announces the discovery of a CVE-2026-28289 vulnerability in FreeScout that allows unauthenticated, zero-click remote code execution via email, with a reference to a report that likely includes a PoC.

    02031624
    60.0K followersView on X
  • ET Labs@ET_Labs
    General

    35 new OPEN, 45 new PRO (35 + 10) EvilTokens, Apace ActiveMQ Jolokia (CVE-2026-34197), Citrix Netscaler (CVE-2026-3055), FreeScout Mail2Shell (CVE-2026-28289), Lumma Stealer, NetSupport RAT, TA569, TORG, ZPHP https://community.emergingthreats.net/t/ruleset-update-summary-2026-04-08-v11167/3258

    Post summary

    The post provides a brief community threat update naming several CVEs, but offers no actionable details, tools, or evidence of exploitation.

    04000313
    5.7K followersView on X
  • キタきつね@foxbook
    Disclosure

    FreeScout の脆弱性により、メール経由で認証されていないゼロクリック RCE が可能になる (CVE-2026-28289) FreeScout vulnerability enables unauthenticated, zero-click RCE via email (CVE-2026-28289) #HelpNetSecurity (Mar 5) https://www.helpnetsecurity.com/2026/03/05/freescout-vulnerability-cve-2026-28289/

    Post summary

    A new unauthenticated, zero‑click remote code execution vulnerability (CVE‑2026‑28289) for FreeScout has been disclosed, but no exploit code, patch, or active exploitation evidence is mentioned.

    00021266
    4.7K followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    Disclosure

    FreeScout vulnerability enables unauthenticated, zero-click RCE via email (CVE-2026-28289) https://www.helpnetsecurity.com/2026/03/05/freescout-vulnerability-cve-2026-28289/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet announces that FreeScout has a new unauthenticated, zero‑click remote code execution vulnerability (CVE‑2026‑28289) that can be triggered via email, without providing a PoC, patch advice, or evidence of active exploitation.

    01020574
    193.5K followersView on X
  • maru@maru1151157
    Patch

    🚨 CVE-2026-28289 (CVSS: 10.0) FreeScout 1.8.206以前で、認証ユーザーがアップロード許可を持つ場合、ゼロ幅スペースで前缀した悪意のある.htaccessファイルをアップロードし、リモートコード実行(RCE)を可能にするTOCTOU脆弱性。1.8.207で修正。 https://maruomosquit.com/vulnerability/CVE-2026-28289/ #脆弱性 #セキュリティ

    Post summary

    CVE-2026-28289 is a CVSS 10 RCE in FreeScout caused by a TOCTOU bug; the issue is fixed in version 1.8.207, with a link to the advisory provided.

    10020143
    1.5K followersView on X
  • iototsecnews@iototsecnews
    Patch

    FreeScout の RCE 脆弱性 CVE-2026-28289 が FIX:メール送信のみでサーバ乗っ取りが可能 https://iototsecnews.jp/2026/03/05/mail2shell-zero-click-attack-lets-hackers-hijack-freescout-mail-servers/ 今回の脆弱性である CVE-2026-28289 は、 FreeScout のファイル・アップロード時における検証プロセスの不備に起因するものです。以前の修正で導入されたファイル名のチェックは、不可視文字であるゼロ幅スペースを用いる戦術で、巧妙に回避できてしまうところに問題の核心があります。 この特殊な文字が、フィルタリングをすり抜けた後にシステム内で削除されることで、結果として制限されていたはずの危険なファイルが保存されてしまいます。メールを受信するだけでプログラムが実行されるゼロクリック攻撃につながるため、認証を持たない外部の攻撃者であっても、サーバを操作できるというリスクが生じます。最新版の version 1.8.207 への更新を急いでください。 #CVE202628289 #FreeScout #Vulnerability

    Post summary

    CVE-2026-28289 is a remote code execution flaw in FreeScout’s file‑upload logic that can be triggered by a zero‑click mail attack; users are urged to update to version 1.8.207 to mitigate the risk.

    01001128
    484 followersView on X
  • Poseidon@PoseidonTPA
    Disclosure

    FreeScout vulnerability enables unauthenticated, zero-click RCE via email (CVE-2026-28289) http://news.poseidon-us.com/TRJgmC #HelpNetSecurity #Cybersecurity https://t.co/p4882Y73cm

    Post summary

    A new CVE (2026-28289) for FreeScout has been disclosed, indicating an unauthenticated, zero‑click RCE via email, but no exploit or patch details are provided.

    1001055
    757 followersView on X
  • Lorenzo Ordóñez@lordman1982
    General

    FreeScout Zero-Click RCE (CVE-2026-28289) – Patch Bypass https://buff.ly/Xccsc7I

    Post summary

    The brief announcement references a zero-click RCE in FreeScout but offers no evidence of exploits, detailed vulnerability characteristics, or mitigation steps.

    0001089
    1.6K followersView on X
  • Eric Vanderburg@evanderburg
    Disclosure

    #FreeScout vulnerability enables unauthenticated, zero-click RCE via email (#CVE-2026-28289) http://securitytc.com/TRJg28 https://t.co/yn9aWe29gI

    Post summary

    The tweet announces a new CVE-2026-28289 vulnerability in FreeScout that allows unauthenticated, zero-click remote code execution via email. No PoC, patch, or exploitation evidence is provided.

    00010117
    44.2K followersView on X
  • Shah Sheikh@shah_sheikh
    Disclosure

    FreeScout vulnerability enables unauthenticated, zero-click RCE via email (CVE-2026-28289): A newly discovered vulnerability (CVE-2026-28289) in the open-source help desk platform FreeScout could allow attackers to take over vulnerable servers by sending… https://www.helpnetsecurity.com/2026/03/05/freescout-vulnerability-cve-2026-28289/?utm_source=dlvr.it&utm_medium=twitter https://t.co/f8iFenjTKT

    Post summary

    A newly discovered CVE‑2026‑28289 in FreeScout permits unauthenticated, zero‑click remote code execution via email, with no PoC, exploit, or patch information provided.

    0001054
    2.2K followersView on X
  • Moshe Siman Tov Bustan@MosheTov
    PoC

    @the_yellow_fall Thanks for sharing our research, this is the original post and findings including the exploit POC https://www.ox.security/blog/freescout-rce-cve-2026-28289/

    Post summary

    A new RCE vulnerability (CVE‑2026‑28289) has been disclosed with an accompanying proof‑of‑concept exploit; no patch, mitigation, or evidence of active exploitation is mentioned.

    00010113
    80 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Disclosure

    The FreeScout helpdesk platform faces a zero-click RCE vulnerability (CVE-2026-28289) allowing unauthenticated attackers to hijack servers via crafted email attachments, bypassing a prior fix with zero-width space exploits. #FreeScoutFlaw #RemoteCodeExec https://ift.tt/rXpUAjn

    Post summary

    A new zero‑click RCE vulnerability (CVE‑2026‑28289) in the FreeScout helpdesk platform allows attackers to hijack servers using crafted email attachments, bypassing a prior fix that employed zero‑width space exploits.

    10000168
    3.7K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-28289 - Critical FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier allows any authenticate... https://www.thehackerwire.com/vulnerability/CVE-2026-28289/ https://t.co/aDOfA2i0da

    Post summary

    The post announces a critical patch bypass vulnerability in FreeScout, affecting versions 1.8.206 and earlier, but does not provide PoC, exploit code, or evidence of active exploitation.

    1000060
    121 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28289 Authenticated Remote Code Execution in via Zero-Width Character Space FREESCSCOUTV 1.8)8.206 and Human https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28289

    Post summary

    CVE-2026-28289 is an authenticated remote code execution vulnerability in FREESCSCOUTV 1.8.206 that exploits a zero‑width character space.

    1000066
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-28289: CRITICAL] A patch bypass vulnerability in FreeScout 1.8.206 allows authenticated users to achieve Remote Code Execution by uploading a malicious file. Update to version 1.8.207 to fix.#cve,CVE-2026-28289,#cybersecurity https://cvefind.com/CVE-2026-28289

    Post summary

    The post highlights a critical patch bypass vulnerability in FreeScout 1.8.206 that permits authenticated users to execute remote code via malicious file uploads, and recommends updating to 1.8.207 to remediate.

    1000094
    593 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-28289 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier al… https://www.cve.org/CVERecord?id=CVE-2026-28289 ----- Traducción: CVE-2026-28289 Fre… http://infoflow.cloud`

    Post summary

    The post references CVE‑2026‑28289, noting a patch bypass vulnerability related to CVE‑2026‑27636 in FreeScout, but provides no further technical details, PoC, or exploitation evidence.

    1000060
    55 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-28289 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier al… https://www.cve.org/CVERecord?id=CVE-2026-28289

    Post summary

    The snippet references CVE-2026-28289 as a patch bypass vulnerability in FreeScout but offers no further technical details, exploitation evidence, or mitigation information.

    10000216
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfreescoutfreescout---

Explore more