CVE-2026-28289 is a high-severity patch bypass vulnerability affecting FreeScout versions 1.8.206 and earlier, a PHP-based help desk application. It allows an authenticated user with file upload permissions to achieve Remote Code Execution (RCE) on the server. Rated 8.1 HIGH on the CVSS scale, the vulnerability exploits a Time-of-Check to Time-of-Use (TOCTOU) flaw in the file upload sanitization, enabling the upload of a malicious .htaccess file via a zero-width space character prefix to bypass security checks. While not on CISA's KEV list, this CVE is marked as "Active" on hotlists and has publicly available exploit code, including a Metasploit module, indicating a significant and imminent threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.8.207CPE matchmatch criteria | cpe:2.3:a:freescout:freescout:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
FreeScout Remote Code Execution (CVE-2026-28289)
Mar 15, 2026FreeScout Remote Code Execution (CVE-2026-28289)
Mar 15, 2026FreeScout Remote Code Execution (CVE-2026-28289)
Mar 15, 2026FreeScout Remote Code Execution (CVE-2026-28289)
Mar 15, 2026FreeScout Remote Code Execution (CVE-2026-28289)
Mar 15, 2026