Redpacketsecurity Vulnerabilities in Zammad Ticketing System Under Active Exploitation
Article Content
- •CVE-2026-102489 allows remote code execution via session hijacking in specific versions.
- •CVE-2026-102490 enables local privilege escalation to root across all Zammad versions.
- •Active exploitation is confirmed; immediate upgrades or system shutdowns are recommended.
Two vulnerabilities (CVE-2026-102489 and CVE-2026-102490) have been identified in the Zammad ticketing system, affecting all versions up to 7.1.3. CVE-2026-102489 allows session hijacking leading to remote code execution in versions 6.3.0 to 6.5.4, while CVE-2026-102490 enables local privilege escalation to root across all versions. Both vulnerabilities are actively exploited, with reports indicating that they are trivial to reproduce. Organizations running Zammad versions below 7.0 are urged to upgrade immediately or take their systems offline. The vulnerabilities pose significant risks, including unauthorized access to sensitive ticket data and potential disruption of services. CISA added both CVEs to its Known Exploited Vulnerabilities (KEV) catalog on October 2, 2026, highlighting the urgency for remediation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Zammad GmbH and CVE-2026-102489 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of Zammad are affected?
What actions should I take immediately?
How serious are these vulnerabilities?
Continue Reading
DIVD Breached via AI-Driven Zero-Day Exploits in Zammad The Dutch Institute for Vulnerability Disclosure (DIVD) confirmed a breach involving two zero-day vulnerabilities (CVE-2026-102489 and CVE-2026-102490) in its Zammad helpdesk system. An attacker utilized an AI agent to automate the exploitation process, achieving root access in seconds. The vulnerabilities allowed for…
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…