CISA Adds Zammad Vulnerabilities to KEV Following Active Exploitation
CISA added two exploited Zammad flaws to KEV that chain into root-level remote code execution.
CISA added CVE-2026-102489 and CVE-2026-102490, both in the Zammad helpdesk, to the Known Exploited Vulnerabilities catalog on October 2, 2026, after confirmed active exploitation. CVE-2026-102489 is a session-fixation flaw in versions 6.3.0 through 6.5.4 that can give remote code execution as the Zammad account; combined with CVE-2026-102490, an improper privilege-management bug reported from about version 1.5 through 7.1.0-alpha, it can escalate to root. Federal civilian agencies must remediate by October 5, 2026, under BOD 26-04. Public reporting indicates the chain was the entry point in a breach involving the Dutch Institute for Vulnerability Disclosure; Merlon Security and DIVD are credited with the analysis.
- Both Zammad flaws were added to CISA KEV on October 2, 2026.
- Session fixation plus privilege mismanagement can chain to root.
- Federal agencies must mitigate by October 5, 2026.
- Reports say the chain was used in a DIVD breach.
- Internet-facing Zammad systems need version checks and log review.
Vulnerabilities mentionedAll →
- CVE-2026-1024899.41%Session hijack to RCE in Zammadpublished · Zammad KEV PoC +1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
Full article472 words · extracted from gbhackers.com · click to collapse
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in the Zammad helpdesk platform to its Known Exploited Vulnerabilities (KEV) Catalog following reports of active exploitation.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in the Zammad helpdesk platform to its Known Exploited Vulnerabilities (KEV) Catalog following reports of active exploitation.
The vulnerabilities, tracked as CVE-2026-102489 and CVE-2026-102490, can be combined to achieve remote code execution and ultimately gain root-level access on affected Zammad systems.
CVE-2026-102489 is a session fixation vulnerability (CWE-384) that can allow remote code execution under the local Zammad account.
CISA stated that this issue can be combined with CVE-2026-102490, an improper privilege management flaw (CWE-269), to escalate privileges from the Zammad user to root. Both entries were added to the KEV Catalog on October 2, 2026, with a remediation deadline set for October 5, 2026.
Zammad Vulnerabilities
The first vulnerability affects Zammad versions 6.3.0 through 6.5.4, as noted in the CVE record published by the Dutch Institute for Vulnerability Disclosure (DIVD).
This record describes a session-hijacking condition that leads to remote code execution using the Zammad service account. It also mentions that versions 7.0.0 through 7.1.3 contain the underlying issue but are not exploitable under the documented environmental conditions.
CVE-2026-102490 affects a broader range of releases, reportedly spanning from Zammad 1.5 to 7.1.0-alpha. This flaw lets a local Zammad user escalate to root, turning access gained through the first vulnerability into full control of the underlying host.
Public reports from Zammad community members and third-party researchers indicate that publicly exposed Zammad instances require immediate patching. Indications suggest the chained vulnerabilities were exploited in a breach involving DIVD, where attackers reportedly used the Zammad zero-days as their entry point.
CISA has classified both vulnerabilities as requiring forensic triage under Binding Operational Directive 26-04. While the agency’s KEV entries do not specify ransomware use, the addition to the catalog confirms the vulnerabilities have been exploited in real-world attacks.
Federal civilian executive branch agencies must apply vendor-recommended mitigations by October 5, in accordance with BOD 26-04’s risk-based patching requirements. Organizations using cloud-hosted deployments should follow the applicable cloud-service guidance, while those without available mitigations should discontinue use of affected products, as advised by CISA.
Security teams are urged to identify all internet-facing Zammad deployments, verify installed versions, and investigate logs for any suspicious session activity, unexpected commands executed by the Zammad account, newly created privileged accounts, and changes to authentication or service configurations.
The CVE record credits researchers from Merlon Security and DIVD for discovering and analyzing CVE-2026-102489.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.