TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Infosecurity Magazine

Zero-Click FreeScout Bug Enables Remote Code Execution

2026-03-05 · Read original ↗

ATT&CK techniques detected

2 predictions
T1190Exploit Public-Facing Application
91%
"zero - click freescout bug enables remote code execution security researchers have urged freescout customers to patch a maximum - severity remote code execution ( rce ) vulnerability which needs no user interaction to achieve full system compromise. cve ‑ 2026 ‑ 28289 ( mail2shel…"
T1195Supply Chain Compromise
37%
"day disclosure policy was designed to ensure vendors have more time to perform root cause and variant analysis. in 2022, trend micro ’ s zero day initiative ( zdi ) also complained about poor patch quality across industry, warning that it could be costing customers upwards of $ 4…"

Summary

Ox Security warns that Mail2Shell could enable threat actors to hijack FreeScout systems without user interaction