Zammad 0-Day Vulnerabilities Exploited to Gain Remote Code Execution and Root Access
Attackers exploited two Zammad zero-days for remote code execution and root, including a breach of DIVD.
Two Zammad zero-days, CVE-2026-102489 and CVE-2026-102490, were exploited in the wild, including against the Dutch Institute for Vulnerability Disclosure on 21 September 2026. CVE-2026-102489 is a session-hijacking flaw in Zammad 6.3.0 through 6.5.4 that can lead to remote command execution as the Zammad service user; the issue also exists in 7.0.0–7.1.3 but researchers said those releases were not exploitable under observed conditions. CVE-2026-102490 is a local privilege escalation to root affecting every version from 1.5.0 through 7.1.0-alpha. Chained, the bugs can yield full server control, ticket and attachment theft, and persistence; DIVD reported the issues on 24 September and recommends upgrading to version 7 or taking systems offline while noting the privilege-escalation bug still affects version 7.