<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Critical Zero-Click Flaw Lets Hackers Hijack FreeScout Mail Servers

"Mail2Shell" zero-click flaw in FreeScout risks server hijacks. Update now to protect against unauthorized data access.
Content Team

Security researchers discovered a critical zero-click vulnerability called "Mail2Shell" in FreeScout, a popular open-source help desk application. The flaw (CVE-2026-28289) allows attackers to completely hijack mail servers without any user interaction or authentication.

The attack exploits a bypass in a recent security patch by using a hidden Unicode character (Zero-Width Space) in malicious email attachments. When FreeScout processes these crafted emails, the hidden character slips past security filters but gets stripped later, leaving dangerous files on the server.

With over 1,100 publicly exposed FreeScout instances used by healthcare, finance, and tech companies, this vulnerability poses serious risks. Successful attacks can lead to complete server takeover, data theft, and network infiltration. FreeScout released version 1.8.207 to fix the issue - administrators must update immediately.

Source: Cyber Security News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo