U.S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog
CISA added two exploited Zammad zero-days to KEV after attackers chained them to breach DIVD.
CISA added CVE-2026-102489 and CVE-2026-102490, both CVSS 9.4, to the Known Exploited Vulnerabilities catalog. CVE-2026-102489 is a session-fixation flaw in Zammad 6.3.0–6.5.4 and 7.0.0–7.1.3 that can yield remote code execution as the zammad user; CVE-2026-102490 is local privilege escalation to root from version 1.5.0 through 7.1.0-alpha. The Dutch Institute for Vulnerability Disclosure said attackers chained the zero-days in its Zammad helpdesk, reached root within seconds with an AI agent, and exfiltrated data before segmentation limited spread. Zammad has more than 2,000 customers and 55,000 users; CISA set a federal fix deadline of October 5, 2026, and DIVD urged operators to update to version 7 or take systems offline.