CISA Adds New Vulnerabilities to KEV Catalog: Zammad and Citrix
Article Content
- •CISA added CVE-2026-102489 and CVE-2026-102490 to the KEV Catalog on 2026-10-02.
- •CVE-2026-88779 was added to the KEV Catalog on 2026-10-04.
- •All organizations are encouraged to prioritize the remediation of KEV vulnerabilities.
CISA has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. CVE-2026-102489, a session fixation vulnerability in Zammad, and CVE-2026-102490, an improper privilege management vulnerability in Zammad, were added on 2026-10-02. Additionally, CVE-2026-88779, an improper restriction of operations vulnerability in Citrix NetScaler, was added on 2026-10-04. These vulnerabilities pose significant risks to federal agencies and other organizations. CISA's Binding Operational Directive 26-04 mandates rapid remediation of high-risk vulnerabilities for Federal Civilian Executive Branch agencies. CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV vulnerabilities. The agency will continue to update the catalog with new vulnerabilities as they are identified.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Citrix and CVE-2026-102489 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What are the CVEs added to the KEV Catalog?
Who is affected by these vulnerabilities?
What actions should organizations take?
Continue Reading
Vulnerabilities in Zammad Ticketing System Under Active Exploitation Two vulnerabilities (CVE-2026-102489 and CVE-2026-102490) have been identified in the Zammad ticketing system, affecting all versions up to 7.1.3. CVE-2026-102489 allows session hijacking leading to remote code execution in versions 6.3.0 to 6.5.4, while CVE-2026-102490 enables local privilege escalation to root…
DIVD Breached via AI-Driven Zero-Day Exploits in Zammad The Dutch Institute for Vulnerability Disclosure (DIVD) confirmed a breach involving two zero-day vulnerabilities (CVE-2026-102489 and CVE-2026-102490) in its Zammad helpdesk system. An attacker utilized an AI agent to automate the exploitation process, achieving root access in seconds. The vulnerabilities allowed for…