Skip to content
Vulnerabilities in Zammad Ticketing System Under Active Exploitation

Vulnerabilities in Zammad Ticketing System Under Active Exploitation

First seen 4 Oct 2026, 04:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 06:06 UTC

Two vulnerabilities (CVE-2026-102489 and CVE-2026-102490) have been identified in the Zammad ticketing system, affecting all versions up to 7.1.3. CVE-2026-102489 allows session hijacking leading to remote code execution in versions 6.3.0 to 6.5.4, while CVE-2026-102490 enables local privilege escalation to root across all versions. Both vulnerabilities are actively exploited, with reports indicating that they are trivial to reproduce. Organizations running Zammad versions below 7.0 are urged to upgrade immediately or take their systems offline. The vulnerabilities pose significant risks, including unauthorized access to sensitive ticket data and potential disruption of services. CISA added both CVEs to its Known Exploited Vulnerabilities (KEV) catalog on October 2, 2026, highlighting the urgency for remediation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-30
CVE-2026-102489 and CVE-2026-102490 published
Both vulnerabilities were published, highlighting critical flaws in the Zammad ticketing system.
Redpacketsecurity
2026-10-02
CISA adds CVEs to KEV catalog
CISA confirmed active exploitation of both CVEs and added them to the Known Exploited Vulnerabilities catalog.
Redpacketsecurity
2026-10-03
Horizon3.ai reports on vulnerabilities
Horizon3.ai confirmed that both vulnerabilities are actively exploited and trivial to reproduce.
X

More articles in this cluster (3)

Following this threat?

Track Zammad GmbH and CVE-2026-102489 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of Zammad are affected?
Versions 6.3.0 to 6.5.4 are vulnerable to CVE-2026-102489, while all versions are affected by CVE-2026-102490.
What actions should I take immediately?
Upgrade to Zammad version 7.0 or later, or take your Zammad instances offline until patched.
How serious are these vulnerabilities?
Both vulnerabilities are rated as critical, with active exploitation confirmed, posing significant risks to affected systems.