Skip to content
Horizon3.ai on X: "Exploitation Risk alert: Critical vulnerabilities in Zammad ticketing system ...

Horizon3.ai on X: "Exploitation Risk alert: Critical vulnerabilities in Zammad ticketing system ...

X • October 3, 2026

Critical vulnerabilities in Zammad ticketing system, trivial to reproduce per our attack engineer. Two flaws allow attackers to:

🔴 CVE-2026-102489 — Session hijacking → Remote Code Execution (versions 6.3-6.5.4)

🔴 CVE-2026-102490 — Local privilege escalation to root (all versions)

This is being actively exploited: if you're running Zammad < v7, upgrade now or take it offline."

Critical vulnerabilities in Zammad ticketing system, trivial to reproduce per our attack engineer. Two flaws allow attackers to:

🔴 CVE-2026-102489 — Session hijacking → Remote Code Execution (versions 6.3-6.5.4)

🔴 CVE-2026-102490 — Local privilege escalation to root (all versions)

This is being actively exploited: if you're running Zammad < v7, upgrade now or take it offline.

vulnerabilities, CVE-2026-102489 and CVE-2026-102490 which been exploited in the wild and lead to RCE, are trivially reproducible.

We expect that most instances that haven’t yet been targeted by the original attackers will soon

Critical vulnerabilities in Zammad ticketing system, trivial to reproduce per our attack engineer. Two flaws allow attackers to:

🔴 CVE-2026-102489 — Session hijacking → Remote Code Execution (versions 6.3-6.5.4)

🔴 CVE-2026-102490 — Local privilege escalation to root (all versions)

This is being actively exploited: if you're running Zammad < v7, upgrade now or take it offline.

vulnerabilities, CVE-2026-102489 and CVE-2026-102490 which been exploited in the wild and lead to RCE, are trivially reproducible.

We expect that most instances that haven’t yet been targeted by the original attackers will soon

Affected NodeZero Rapid Response customers have been assessed for exposure and notified.