Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-28289

62
FAUCET Score

CVE-2026-28289 is a high-severity patch bypass vulnerability affecting FreeScout versions 1.8.206 and earlier, a PHP-based help desk application. It allows an authenticated user with file upload permissions to achieve Remote Code Execution (RCE) on the server. Rated 8.1 HIGH on the CVSS scale, the vulnerability exploits a Time-of-Check to Time-of-Use (TOCTOU) flaw in the file upload sanitization, enabling the upload of a malicious .htaccess file via a zero-width space character prefix to bypass security checks. While not on CISA's KEV list, this CVE is marked as "Active" on hotlists and has publicly available exploit code, including a Metasploit module, indicating a significant and imminent threat.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.8.207CPE matchmatch criteria
cpe:2.3:a:freescout:freescout:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

10.0CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
31.14%
Probability of exploitation in next 30 days
EPSS Percentile
98.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
Metasploit: FreeScout Unauthenticated RCE via ZWSP .htaccess Bypass · Mar 1, 2026
This CVE's current EPSS score of 0.3114 is in the 98th percentile among its peer group of 1,162 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

github_advisorypatch availablevia nvd_reference
View patch
amazonvendor investigatingvia llm_extracted
horillavendor investigatingvia llm_extracted
jitsivendor investigatingvia llm_extracted
leantimevendor investigatingvia llm_extracted
nutanixvendor investigatingvia llm_extracted

Vendor Advisories (5)

leantimellm-leantime-ea57f2fd6196f8e9HIGH

FreeScout Remote Code Execution (CVE-2026-28289)

Mar 15, 2026
amazonllm-amazon-904811c19d21ffedHIGH

FreeScout Remote Code Execution (CVE-2026-28289)

Mar 15, 2026
nutanixllm-nutanix-920e2f1f59a493baHIGH

FreeScout Remote Code Execution (CVE-2026-28289)

Mar 15, 2026
horillallm-horilla-3c8f273bf58467b0HIGH

FreeScout Remote Code Execution (CVE-2026-28289)

Mar 15, 2026
jitsillm-jitsi-e6d25433eee6a01aHIGH

FreeScout Remote Code Execution (CVE-2026-28289)

Mar 15, 2026

References

ox.security / blog/freescout-rce-cve-2026-28289
ExploitVendor Advisory
github.com / freescout-help-desk/freescout/commit/f7bc16c56a6b13c06da52ad51fd666546b40818f
Patch
github.com / freescout-help-desk/freescout/security/advisories/GHSA-5gpc-65p8-ffwp
ExploitMitigationVendor Advisory