Image for Article: Mail2Shell zero-click attack lets hackers hijack FreeScout mail servers

Article Details

Title
Article: Mail2Shell zero-click attack lets hackers hijack FreeScout mail servers
Impact Score
6 / 10
AI Summary (Processed Content)

A critical vulnerability (CVE-2026-28289) in the FreeScout helpdesk platform allows unauthenticated, remote code execution via a malicious email attachment. Attackers bypass a previous patch by using a zero-width space character in a filename, which circumvents security checks and enables server compromise. The flaw affects all versions up to 1.8.206, is patched in version 1.8.207, and requires immediate updating. While no active exploits are currently reported, the risk is considered high due to the vulnerability's severity and ease of exploitation.

The main topics covered are the technical details of a severe software vulnerability, its method of exploitation, the affected software versions and patch status, and the potential consequences and recommendations for mitigation.

Original URL
https://www.bleepingcomputer.com/news/security/mail2shell-zero-click-attack-lets-hackers-hijack-freescout-mail-servers/
Source Feed
BleepingComputer
Published Date
2026-03-04 21:51
Fetched Date
2026-03-04 22:46
Processed Date
2026-03-04 22:48
Embedding Status
Present
Cluster ID
Not Clustered
Raw Extracted Content