CISA added two vulnerabilities affecting the self-hosted Zammad help desk platform to its Known Exploited Vulnerabilities catalog on October 2, following reports of active exploitation. CVE-2026-102489 is a session fixation flaw rated CVSS 8.7 that can enable remote session hijacking and potentially code execution as the local zammad user. CVE-2026-102490, rated CVSS 8.5, reportedly allows that user to escalate privileges to root, creating a potential chained compromise. Zammad disputes the privilege escalation report, saying DIVD has not provided sufficient technical details to confirm the vulnerability or identify affected releases. CISA lists ransomware campaign use as unknown for both flaws.
CISA set an October 5, 2026 remediation deadline for both entries and requires forensic triage, assessment of internet exposure, and action under vendor mitigations and BOD 26-04 guidance, including discontinuing use if mitigations are unavailable. Zammad 7.2.0 includes hardening for CVE-2026-102489, but runZero reported that no official patch for CVE-2026-102490 was available at publication. Security teams should urgently inventory Zammad deployments, prioritize internet-facing instances, apply available vendor hardening, and investigate possible compromise rather than treating an upgrade alone as complete remediation.

See which actors are running it and whether you're in range.
8 events from the most recent confirmed update back to the earliest known activity.
CISA added CVE-2026-102489 and CVE-2026-102490 to its Known Exploited Vulnerabilities catalog, requiring forensic triage and vendor-directed mitigations under BOD 26-04. Both entries set an October 5, 2026 remediation deadline and list ransomware campaign use as unknown.
DIVD published a CVE record describing session hijacking that can lead to remote code execution as the zammad user, reporting CVSS v4.0 scores of 8.7 and 9.4. The description lists versions 6.3.0–6.5.4 as vulnerable, but the structured affected range excludes 6.5.4; versions 7.0.0–7.1.3 are described as containing the flaw without practical exploitability under their environmental conditions.
DIVD published a CVE record alleging that the local Zammad user can escalate privileges to root on Linux and Docker deployments. The structured affected range runs from 1.5.0 to before 7.1.0-alpha, conflicting with the description's inclusion of the latest alpha; no fix or technical exploitation details were provided.
Zammad disputes CVE-2026-102490, stating that DIVD has not supplied sufficient technical details to confirm the flaw, its scope, or affected releases. No official patch for this reported vulnerability was available at the reference's publication.
Zammad version 7.2.0 includes security hardening to resolve CVE-2026-102489. The reference identifies versions 6.3.0 through 6.5.4 as directly affected, while versions 7.0.0 through 7.1.3 reportedly contain the underlying flaw without practical exploitability under their runtime conditions.
The runZero reference reports evidence of active exploitation of CVE-2026-102489 and CVE-2026-102490 in the wild. The vulnerabilities can potentially be chained to progress from remote session compromise to root-level control of the host.
DIVD identified CVE-2026-102489 and CVE-2026-102490 under case DIVD-2026-00015 while investigating a separate incident. The flaws involve session fixation potentially enabling code execution as the zammad user and a reported local privilege escalation to root.
A vulnerability was exploited to breach DIVD on September 21, 2026, prompting the investigation that uncovered the two Zammad flaws. The advisory does not specify which of the two CVEs was exploited in the breach.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
9 references tracked. Mallory keeps watching after this page renders.
runzero.com
Open sourcegithub.com
Open sourcecve.mitre.org
Open sourcecve.org
Open sourcecve.org
Open sourcecve.mitre.org
Open sourcecsirt.divd.nl
Open sourcecsirt.divd.nl
Open sourcecsirt.divd.nl
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.