{"id":11123,"date":"2026-03-05T10:03:50","date_gmt":"2026-03-05T10:03:50","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/03\/05\/mail2shell-zero-click-attack-lets-hackers-hijack-freescout-mail-servers\/"},"modified":"2026-03-05T10:03:50","modified_gmt":"2026-03-05T10:03:50","slug":"mail2shell-zero-click-attack-lets-hackers-hijack-freescout-mail-servers","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/03\/05\/mail2shell-zero-click-attack-lets-hackers-hijack-freescout-mail-servers\/","title":{"rendered":"Mail2Shell Zero-Click Attack lets Hackers Hijack FreeScout Mail Servers"},"content":{"rendered":"<p>    Mail2Shell Zero-Click Attack lets Hackers Hijack FreeScout Mail Servers<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Researchers have uncovered a critical <a href=\"https:\/\/cybersecuritynews.com\/gemini-zero-click-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">zero-click vulnerability<\/a> in FreeScout, a widely used open-source help desk and shared mailbox application.<\/p>\n<p>Dubbed \u201cMail2Shell,\u201d this flaw allows attackers to <a href=\"https:\/\/cybersecuritynews.com\/enterprise-email-threads-leveraged\/\" target=\"_blank\" rel=\"noreferrer noopener\">hijack mail servers<\/a> without any user interaction or authentication.<\/p>\n<p>The vulnerability, tracked as CVE-2026-28289, bypasses a recently patched Remote Code Execution (RCE) flaw, escalating it into an unauthenticated zero-click attack.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-the-zero-click-escalation-path\"><strong>The Zero-Click Escalation Path<\/strong><\/h2>\n<p>Just days after FreeScout patched an <a href=\"https:\/\/cybersecuritynews.com\/grandstream-gxp1600-voip-phones-rce-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">authenticated RCE vulnerability<\/a> (CVE-2026-27636), security analysts found a way to bypass the incomplete fix.<\/p>\n<p>The original patch attempted to block dangerous file uploads by appending an underscore to files with restricted extensions or names starting with a period.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi4KpDNyzpFrSiR6WGRGhXsqSWy_pc6BdFkP1YvcH6FyhGsv6grnMavGi2_7ZvxxZUYTUKWLqQhvkUUIKjs902Tob3YnZx6hLFV_n7qE3_mLLJehPp1hr3xef4Wd9W24tfhyphenhyphenA3gTEwg_nsgtXINbUTNu2IA5ShE_Ge_ruRJV8meI-5KXOu5JI-ua_bHwk4\/s1600\/Screenshot%25202026-03-05%2520104822%2520%25281%2529.webp?ssl=1\" alt=\"Attack Graph (source : OX. Security)\"><figcaption class=\"wp-element-caption\">Attack Graph (source: OX. Security)<\/figcaption><\/figure>\n<p>However, attackers can easily bypass this validation by prepending a <a href=\"https:\/\/cybersecuritynews.com\/phishing-attack-using-zero-width-characters\/\" target=\"_blank\" rel=\"noreferrer noopener\">Zero-Width Space character <\/a>(Unicode U+200B) to the malicious filename.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhrm8CVo8QXOoxk1H2ub7UVR60ooEyIO8vH-vpFTyOrFMdP00sQTfhzA5C8phb2uQs_plf1Sl1x4eNMEN0lC-EzCEPESnn24AQdkignigGQEuo7ATDIiS-4m4qmc5NGuqufLRq1NF-Jjt5dmwbNjdzarV88EmXz5HMprlnSUme8qovGW_lBdHmRgx4MLcc\/s1600\/Screenshot%25202026-03-05%2520105308%2520%25281%2529.webp?ssl=1\" alt=\"Blocked risky uploads via underscores(source : OX. Security)\"><figcaption class=\"wp-element-caption\">Blocked risky uploads via underscores (source: OX. Security)<\/figcaption><\/figure>\n<p>Because the system does not treat this hidden character as visible content during the initial security check, the file slips past the filter.<\/p>\n<p>Later in the processing chain, the server strips the U+200B character, leaving the payload as a dangerous dotfile.<\/p>\n<p>To exploit this, an attacker sends a <a href=\"https:\/\/cybersecuritynews.com\/react-server-vulnerability-exploited\/\" target=\"_blank\" rel=\"noreferrer noopener\">crafted email containing the malicious payload<\/a> to any address connected to the FreeScout server.<\/p>\n<p>The system automatically writes the file to disk in a predictable directory (\/storage\/attachment\/\u2026).<\/p>\n<p>The hacker can then navigate to the payload via the web interface and execute remote commands instantly. This entire chain requires absolutely no authentication and no interaction from the victim.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-impact-and-immediate-mitigation\"><strong>Impact and Immediate Mitigation<\/strong><\/h2>\n<p>FreeScout is heavily utilized by public health institutions, financial platforms, and technology providers to manage customer support.<\/p>\n<p>Built on the <a href=\"https:\/\/cybersecuritynews.com\/laravel-framework-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Laravel PHP framework<\/a>, FreeScout has over 1,100 publicly exposed instances, making it a highly lucrative target for threat actors.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjA0fRki0SBp2QHVcwpMePu2yJ6BwIxZmHBCi3BoeuOSxuoV2BeNKfDCpsHHZ7uG6uZhOZSoCpR90aaHoYjlBVW-vS7Aiun67Ldvakv1TqPyUe_r6p6xk1jjzukzsXUfRXvNbjwwPURCYf5xYRYC6SdjpAvqRvylxc3K6jB6EiV0ojJdFcRVrgb9togS0c\/s1600\/Screenshot%25202026-03-05%2520105233%2520%25281%2529.webp?ssl=1\" alt=\"Bypass confirmed, escalating to unauthenticated RCE(source :OX. Security)\"><figcaption class=\"wp-element-caption\">Bypass confirmed, escalating to unauthenticated RCE(source :OX. Security)<\/figcaption><\/figure>\n<p><a href=\"https:\/\/www.ox.security\/blog\/freescout-rce-cve-2026-28289\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">According to OX Security researchers<\/a>, if exploited, the Mail2Shell vulnerability can lead to complete server takeover.<\/p>\n<p>Hackers can exfiltrate sensitive helpdesk tickets, <a href=\"https:\/\/cybersecuritynews.com\/netflix-phishing-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">steal customer inbox data<\/a>, and use the compromised host to move laterally across the organization\u2019s network.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiR-cNx4yqR6ahG-jBhTnabP4vMKT2ls8IrHSh1_OVdlWqCQBsMMaTWuWYGppv00CodoFdhf05wL3MxuIUs9vgCgbKwNozJYRHOXSEKfTbuToso1tVzj_9fjBlRzj9_zzhLiWzvECmZItBIujfMHSSpv_OTqMryAgk4krBg7Q1THNYmWGr0ePGs1tmQsmI\/s1600\/Screenshot%25202026-03-05%2520105253%2520%25281%2529.webp?ssl=1\" alt=\"Payload accessed, enabling remote server commands(source : OX. Security)\"><figcaption class=\"wp-element-caption\">Payload accessed, enabling remote server commands(source : OX. Security)<\/figcaption><\/figure>\n<p>The FreeScout maintainers responded quickly by releasing version 1.8.207 to close the variant attack path.<\/p>\n<p>Administrators must apply this update immediately, as an older patch does not protect against this zero-click escalation.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/hackers-hijack-freescout-mail-servers\/\">Mail2Shell Zero-Click Attack lets Hackers Hijack FreeScout Mail Servers<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/hackers-hijack-freescout-mail-servers\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Mail2Shell Zero-Click Attack lets Hackers Hijack FreeScout Mail Servers Researchers have uncovered a critical zero-click vulnerability in FreeScout, a widely used open-source help desk and shared mailbox application. Dubbed \u201cMail2Shell,\u201d this flaw allows attackers to hijack mail servers without any user interaction or authentication. The vulnerability, tracked as CVE-2026-28289, bypasses a recently patched Remote Code [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,648],"tags":[130],"class_list":["post-11123","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11123"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11123"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11123\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11123"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11123"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11123"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}