Skip to content
ThreatCluster

CISA Adds New Vulnerabilities to KEV Catalog: Zammad and Citrix

First seen 5 Oct 2026, 03:02 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 5, 2026 at 04:02 UTC
  • •CISA added CVE-2026-102489 and CVE-2026-102490 to the KEV Catalog on 2026-10-02.
  • •CVE-2026-88779 was added to the KEV Catalog on 2026-10-04.
  • •All organizations are encouraged to prioritize the remediation of KEV vulnerabilities.

CISA has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. CVE-2026-102489, a session fixation vulnerability in Zammad, and CVE-2026-102490, an improper privilege management vulnerability in Zammad, were added on 2026-10-02. Additionally, CVE-2026-88779, an improper restriction of operations vulnerability in Citrix NetScaler, was added on 2026-10-04. These vulnerabilities pose significant risks to federal agencies and other organizations. CISA's Binding Operational Directive 26-04 mandates rapid remediation of high-risk vulnerabilities for Federal Civilian Executive Branch agencies. CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV vulnerabilities. The agency will continue to update the catalog with new vulnerabilities as they are identified.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-30
CVE-2026-102489 published
Zammad Session Fixation Vulnerability disclosed with a CVSS score of 8.7.
Cisa
2026-10-02
CVE-2026-102489 and CVE-2026-102490 added to KEV
CISA confirmed active exploitation of both vulnerabilities in Zammad.
Cisa
2026-10-04
CVE-2026-88779 added to KEV
CISA added a Citrix NetScaler vulnerability to the KEV Catalog due to active exploitation.
Cisa

More articles in this cluster (2)

Following this threat?

Track Citrix and CVE-2026-102489 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What are the CVEs added to the KEV Catalog?
CVE-2026-102489, CVE-2026-102490, and CVE-2026-88779 were added due to active exploitation.
Who is affected by these vulnerabilities?
Federal Civilian Executive Branch agencies are primarily affected, but all organizations should prioritize remediation.
What actions should organizations take?
Organizations should prioritize patching the vulnerabilities listed in the KEV Catalog as per CISA's guidance.