Frequency
4
occurrences
First Seen
October 2, 2026
Last Seen
October 3, 2026
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—
Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
Two vulnerabilities (CVE-2026-102489 and CVE-2026-102490) have been identified in the Zammad ticketing system, affecting all versions up to 7.1.3. CVE-2026-102489 allows session hijacking leading to remote code execution in versions 6.3.0 to 6.5.4, while CVE-2026-102490 enables local privilege escal...
The Dutch Institute for Vulnerability Disclosure (DIVD) confirmed a breach involving two zero-day vulnerabilities (CVE-2026-102489 and CVE-2026-102490) in its Zammad helpdesk system. An attacker utilized an AI agent to automate the exploitation process, achieving root access in seconds. The vulnerab...
Public Exploits
Checking GitHub for proof-of-concept code…