Zammad Zero-Days CVE-2026-102489/102490 Chained for RCE and Root, Exploited Against DIVD
Two Zammad vulnerabilities disclosed by DIVD and Merlon Security enable session hijacking, remote code execution, and root escalation when chained (CVSS 9.4); the chain was used in a 21 September 2026 attack on DIVD's own infrastructure, with fixes shipped in…
DIVD and Merlon Security disclosed two Zammad vulnerabilities exploited in the wild, including against DIVD's own infrastructure on 21 September 2026 — an intrusion that completed in seconds, which DIVD attributes to an agentic AI-powered workflow. CVE-2026-102489 is a session-hijacking flaw leading to remote code execution as the Zammad service user, affecting Zammad 6.3.0–6.5.4; the flaw also exists in 7.0.0–7.1.3, but researchers said those releases were not exploitable under observed conditions. CVE-2026-102490 is a local privilege escalation to root affecting every version from 1.5.0 through 7.1.0-alpha. Chained, the bugs carry a CVSS of 9.4 and can yield full server control, ticket and attachment theft, and persistence. DIVD reported the issues on 24 September 2026 and recommends upgrading — GBHackers states fixes are included in Zammad 7.2.0 — or taking systems offline, while hunting for persistence; Cyber Security News notes the privilege-escalation bug still affects version 7 releases, and DIVD is scanning for and notifying owners of exposed vulnerable public instances.
- Vulnerabilities: CVE-2026-102489 and CVE-2026-102490, disclosed by DIVD and Merlon Security; DIVD reported the issues on 24 September 2026.
- CVE-2026-102489 enables session hijacking and remote code execution as the Zammad service user; it affects Zammad 6.3.0–6.5.4, and while it also exists in 7.0.0–7.1.3, researchers said those releases were not exploitable under observed…
- CVE-2026-102490 is a local privilege escalation to root affecting Zammad 1.5.0 through 7.1.0-alpha.
- Chained, the two flaws carry a CVSS of 9.4 and can yield full server control, ticket and attachment theft, and persistence.
- The chain was exploited against DIVD's own infrastructure on 21 September 2026; the intrusion completed in seconds, which DIVD attributes to an agentic AI-powered workflow.
- Fixes are included in Zammad 7.2.0 (per GBHackers); Cyber Security News notes the privilege-escalation bug still affects version 7 — a nuance rather than a direct contradiction, since fixes arrive only in 7.2.0.
- DIVD urges upgrading or taking instances offline, hunting for persistence, and is scanning for vulnerable public instances and notifying their owners.
Coverage timelineoldest first · each row is one article
- · 5h agoZammad 0-Day Vulnerabilities Exploited to Gain Remote Code Execution and Root Access
Cyber Security News· 80
Attackers exploited two Zammad zero-days for remote code execution and root, including a breach of DIVD.
- · 4h agoZammad Vulnerabilities Let Attackers Execute Code and Escalate Privileges to Root
GBHackers· 70
Chained Zammad flaws CVE-2026-102489/102490 enable session hijacking, RCE, and root escalation; already used against DIVD.
Vulnerabilities in this storyAll →
- CVE-2026-1024899.4<1%Session hijack to RCE in Zammadpublished · Zammad KEV+1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
CVE-2026-102489+1 related CVE |