CNC A.I CyberSecurity Scoring
CNC
Company Information
Website:https://www.cybernewscentre.com/
Employees number:3
Number of followers:599
NAICS:51913
Industry Type:Internet Publishing
Homepage:cybernewscentre.com
CNC Risk Score (AI oriented)
Between 700 and 749
CNCInternet Publishing
Updated:
26/03/2026
26/03/2026
747/1000
Moderate
Ba
CNC Global Score (TPRM)
xxxx
CNCInternet Publishing
Score locked

CNCModerate
Current Score
747Ba (MODERATE)
01000
1 incidents
-4 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
748
JUNE 2026
747
MAY 2026
747
APRIL 2026
747
MARCH 2026
751
Vulnerability
05 Mar 2026 • CNC
News Organizations: FreeScout vulnerability enables unauthenticated, zero-click RCE via email (CVE-2026-28289)
Critical FreeScout Vulnerability (CVE-2026-28289) Enables Remote Server Takeover via Malicious Emails
747
CRITICAL-4
CYB1772713930
Critical FreeScout Vulnerability (CVE-2026-28289) Enables Remote Server Takeover via Malicious Emails
A newly disclosed vulnerability in FreeScout, an open-source help desk platform, allows attackers to seize control of vulnerable servers by sending a crafted email to a FreeScout mailbox. Tracked as CVE-2026-28289, the flaw is a bypass of a previous patch (CVE-2026-27636) and affects self-hosted instances running on Apache servers with AllowOverride All enabled a common configuration.
The vulnerability stems from inadequate file upload restrictions, specifically the exclusion of .htaccess and .user.ini files from the platform’s blocklist. Attackers can exploit this by prepending a Zero-Width Space (U+200B) character to a malicious filename, evading validation checks. Once uploaded, the file such as a malicious .htaccess configuration can redefine server behavior, enabling remote code execution (RCE).
Exploitation requires no authentication or user interaction; attackers simply email a payload containing a malicious .htaccess file and a webshell to a FreeScout mailbox. The predictable file storage location allows attackers to access and execute commands via the server’s web interface, leading to full system compromise, data exfiltration (including helpdesk tickets and mailbox content), and potential lateral movement within the network.
Researchers at OX Security identified roughly 1,100 publicly exposed FreeScout instances via Shodan, though the exact number of vulnerable deployments remains unclear. Affected organizations span public health institutions, financial services, technology providers, and news organizations, with researchers withholding specific details to prevent targeted attacks.
FreeScout v1.8.207 patches the vulnerability, and users are advised to upgrade immediately. Additionally, disabling AllowOverride All in Apache’s configuration mitigates the risk. The flaw underscores the ongoing risks of self-hosted, open-source platforms with insufficient input validation.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
751
JANUARY 2026
751
DECEMBER 2025
751
NOVEMBER 2025
751
OCTOBER 2025
751
SEPTEMBER 2025
751
AUGUST 2025
751
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for CNC ??
What was CNC's A.I Rankiteo Cyber Score in June 2026 ??
What was CNC's A.I Rankiteo Cyber Score in May 2026 ??
What was CNC's A.I Rankiteo Cyber Score in April 2026 ??
What was CNC's A.I Rankiteo Cyber Score in March 2026 ??
What was CNC's A.I Rankiteo Cyber Score in February 2026 ??
What was CNC's A.I Rankiteo Cyber Score in January 2026 ??
What was CNC's A.I Rankiteo Cyber Score in December 2025 ??
What was CNC's A.I Rankiteo Cyber Score in November 2025 ??
What was CNC's A.I Rankiteo Cyber Score in October 2025 ??
What was CNC's A.I Rankiteo Cyber Score in September 2025 ??
What was CNC's A.I Rankiteo Cyber Score in August 2025 ??
What is the average per-incident point impact on CNC's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with CNC ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view CNC's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?