Back X Horizon3.ai on X: "Exploitation Risk alert: Critical vulnerabilities in Zammad ticketing system ...
Critical vulnerabilities in Zammad ticketing system, trivial to reproduce per our attack engineer. Two flaws allow attackers to:
🔴 CVE-2026-102489 — Session hijacking → Remote Code Execution (versions 6.3-6.5.4)
🔴 CVE-2026-102490 — Local privilege escalation to root (all versions)
This is being actively exploited: if you're running Zammad < v7, upgrade now or take it offline."
Critical vulnerabilities in Zammad ticketing system, trivial to reproduce per our attack engineer. Two flaws allow attackers to:
🔴 CVE-2026-102489 — Session hijacking → Remote Code Execution (versions 6.3-6.5.4)
🔴 CVE-2026-102490 — Local privilege escalation to root (all versions)
This is being actively exploited: if you're running Zammad < v7, upgrade now or take it offline.
vulnerabilities, CVE-2026-102489 and CVE-2026-102490 which been exploited in the wild and lead to RCE, are trivially reproducible.
We expect that most instances that haven’t yet been targeted by the original attackers will soon
Critical vulnerabilities in Zammad ticketing system, trivial to reproduce per our attack engineer. Two flaws allow attackers to:
🔴 CVE-2026-102489 — Session hijacking → Remote Code Execution (versions 6.3-6.5.4)
🔴 CVE-2026-102490 — Local privilege escalation to root (all versions)
This is being actively exploited: if you're running Zammad < v7, upgrade now or take it offline.
vulnerabilities, CVE-2026-102489 and CVE-2026-102490 which been exploited in the wild and lead to RCE, are trivially reproducible.
We expect that most instances that haven’t yet been targeted by the original attackers will soon
Affected NodeZero Rapid Response customers have been assessed for exposure and notified.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
