All verified exploits

CVE-2026-28289 File Upload Sanitization Bypass (RCE)

Pentest critical FreeScout Added cve-verified-cve-2026-28289

Bypasses filename extension blocklist using zero-width space (U+200B) to upload .htaccess and PHP webshell, achieving remote code execution. Patch bypass for CVE-2026-27636.

Is your app exploitable through CVE-2026-28289?

Scan your domain free