Search
Find merged stories by title or summary.
U.S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog
U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog : • CVE-2026-102489 (CVSS score of 9.4) Zammad GmbH Zammad Session Fixation Vulnerability • CVE-2026-102490 (CVSS score of 9.4) Zammad GmbH Zammad Improper Privilege Management Vulnerability The first flaw, CVE-2026-102489, is a session hijacking vulnerability in Zammad that can lead to remote code execution as the zammad user. It affects Zammad 6. 3. 0 through 6. 5. 4. The flaw is also present in versions 7. 0. 0 through 7. 1. 3. The second flaw, CVE-2026-102490, is a local privilege escalation vulnerability that allows the zammad user to gain root privileges.
Zammad 0-Day Vulnerabilities Exploited to Gain Remote Code Execution and Root Access
Two critical Zammad zero-day flaws , reportedly exploited against the Dutch Institute for Vulnerability Disclosure (DIVD), could allow session hijacking, remote command execution as the Zammad service user, and potential root privilege escalation. The vulnerabilities are tracked as CVE-2026-102489 and CVE-2026-102490. DIVD published the findings under case DIVD-2026-00015 after investigating a separate breach case involving its own environment. An attacker exploited CVE-2026-102489 to compromise DIVD on September 21, 2026, the session hijacking flaw affects Zammad 6. 3. 0–6. 5. 4 and can enable remote code execution as the Zammad user. The issue also exists in Zammad versions 7. 0. 0 through 7. 1. 3, according to DIVD. However, researchers said it is not exploitable in those releases because of environmental conditions.
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2026-102489 Zammad GmbH Zammad Session Fixation Vulnerability • CVE-2026-102490 Zammad GmbH Zammad Improper Privilege Management Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.
Zammad Vulnerabilities Enable Remote Code Execution and Root Privilege Escalation
Two newly disclosed vulnerabilities in the Zammad open-source helpdesk platform could let attackers achieve remote code execution and then escalate to root on affected servers. DIVD CSIRT identified the flaws, tracked as CVE-2026-102489 and CVE-2026-102490, during its investigation into a separate security incident involving the organization. DIVD said the vulnerabilities were actively abused on September 21, 2026, to breach its own environment. Its researchers subsequently analyzed and reproduced the attack chain before reporting the findings to Zammad on September 24. Zammad Vulnerabilities CVE-2026-102489 affects Zammad versions 6. 3. 0 through 6. 5. 4 and involves a session-hijacking issue that can result in remote code execution under the zammad user account.
AI Agent Chains Zammad Zero-Days To Take Over DIVD Systems in Seconds
DIVD was breached through two Zammad zero-days that let an AI agent reach root in seconds, steal data and pivot to other services before being stopped. The Dutch Institute for Vulnerability Disclosure, a nonprofit organization of volunteer security researchers whose whole job is finding and responsibly disclosing vulnerabilities in other people’s software, just disclosed that it got breached through two zero-days in its own ticketing system. The attackers got in through Zammad, an open-source helpdesk platform that DIVD used internally. Working with Merlon Security, DIVD identified two previously unknown vulnerabilities, tracked as CVE-2026-102489 and CVE-2026-102490. Each vulnerability was serious on its own, but chaining them made the attack much more dangerous.
[ENISA] CVE-2026-102490 - Confirmed Exploitation
CVE-2026-102490 ENISA Catalog: Confirmed Status: Yes Exploited: 2026-09-30 00:00 UTC Status Updated: 1 Evidence Sources: 2026-09-30 First Seen: 2026-09-30 Asserted:
You've reached the end of current stories for this search.
