
A critical zero-click Remote Code Execution (RCE)vulnerability, tracked as CVE-2026-28289, has been identified in the open-source helpdesk platform FreeScout. With a maximum CVSS score of 10.0, this flaw allows unauthenticated attackers to gain total control over vulnerable servers.
Vulnerability Overview
The defect is a patch bypass for a previous bug that initially required authentication.
.htaccess. Once saved, the character is stripped, leaving a functional malicious file on the server.Attack Vector and Impact
This exploit is zero-click and requires no authentication.
AllowOverride All are at the highest risk.Remediation
The flaw was addressed in the following update:
AllowOverride settings on Apache.You can track further updates on the FreeScout Security Vulnerabilities Log or via SecurityWeek’s analysis.
#allows #email #news #server #takeover #threat: freescout #unauthenticated #via #vulnerability #zero-click — News
© Bulletproof Servers. All rights reserved.