Zammad Zero-Days (CVE-2026-102489, CVE-2026-102490): Patch Now
CISA added both Zammad zero-days to its KEV catalog after DIVD says an AI agent chained them to hijack a session, run code, and gain root inside its own network.

Two zero-day flaws in the Zammad helpdesk platform — CVE-2026-102489 and CVE-2026-102490 — are now listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, added October 2, 2026, after the Dutch Institute for Vulnerability Disclosure (DIVD) says the pair was chained to break into its own network starting September 21, 2026. Chained together, the two bugs let an outside attacker hijack a Zammad session, run code as the local zammad user, and escalate to full root access on the underlying server. Zammad has published its own security advisory confirming the first bug but disputing how broadly it applies; the second bug has no fix yet. If you run Zammad, especially version 6.5 or earlier, patch or isolate it now.
CVE-2026-102489 — Session fixation / session hijack leading to remote code execution as the zammad user. NVD lists it CVSS 3.1 9.8 (Critical); DIVD, the CVE's assigning authority, separately scores it CVSS 4.0 9.4 (Critical). Zammad says it is only exploitable on 6.5 and earlier; a hardening fix shipped in 7.2.0.
CVE-2026-102490 — Local privilege escalation from the zammad user to root. Same CVSS pattern (NVD 9.8 / DIVD 9.4). No vendor fix is available yet; Zammad says it is tied to a confirmed issue in the third-party packaging tool packager.io and is treating it as a high-priority, in-progress fix.
Added to CISA KEV: October 2, 2026, with a federal civilian remediation due date of October 5, 2026, and a forensic-triage requirement under CISA's binding operational directive guidance.
What happened, in short
On October 2, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two Zammad vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-102489, cataloged as a "Session Fixation Vulnerability," and CVE-2026-102490, cataloged as an "Improper Privilege Management Vulnerability." Both entries carry an October 5, 2026 action date and CISA's note that the two can be chained together — exactly how DIVD says they were used against DIVD's own infrastructure.
Both CVEs were assigned by DIVD itself, acting as the CVE Numbering Authority, after DIVD discovered the flaws were used against its own network. In a public post titled "It was a matter of when, not if…", DIVD said it detected suspicious activity, moved into full incident-response mode, cut off access to its infrastructure, and opened a forensic investigation. DIVD was explicit that it does not yet know the full scope: "we handle this situation as a worst-case-scenario and assume breach until proven otherwise," the organization wrote, and said it would not rule anything out while the investigation continued.
According to DIVD's own account, as it has circulated since the disclosure, the intrusion began on September 21, 2026, was detected the next day, and DIVD worked with an outside incident-response firm to contain it. DIVD has said data belonging to its own volunteer researchers — including DIVD email addresses and potentially other contact details — was taken. None of that breach-timeline detail appears in Zammad's advisory or in CISA's catalog entry; it is DIVD's own characterization of what happened to DIVD, not an independently verified forensic record, and this article treats it accordingly.
The two vulnerabilities, side by side
Here is how the two flaws compare, based on Zammad's advisory, the NVD records for CVE-2026-102489 and CVE-2026-102490 (which DIVD's CSIRT team authored as the assigning CNA), and CISA's catalog entries.
| Detail | CVE-2026-102489 | CVE-2026-102490 |
|---|---|---|
| Type | Session fixation → remote code execution as the zammad user | Local privilege escalation from zammad user to root |
| CVSS (NVD 3.1) | 9.8 Critical | 9.8 Critical |
| CVSS (DIVD 4.0) | 9.4 Critical | 9.4 Critical |
| Affected versions | Zammad says exploitable only on 6.5 and earlier; the bug exists in code through 7.1.3 but Zammad and DIVD's own case notes agree it is not exploitable there in practice | Disputed; DIVD's NVD record lists a wide version range, Zammad has not confirmed the exact affected range and is still analyzing it |
| Prerequisite | Network access to the Zammad instance; can be triggered remotely, unauthenticated | Requires existing local/code-execution access as the zammad user (e.g., gained via CVE-2026-102489) |
| Fix available | Yes — hardening shipped in Zammad 7.2.0 | No — Zammad says it is analyzing the issue as high priority, linked to a packager.io issue |
| Added to CISA KEV | October 2, 2026 | October 2, 2026 |
How the attack chain works
CISA's catalog description and Zammad's advisory agree on the mechanics even where they disagree on scope. CVE-2026-102489 is a session-fixation bug: an attacker can force or hijack a session token in a way that, on affected Zammad builds, leads to code execution running as the low-privileged zammad service account — no valid credentials required first. That alone is serious, since it hands an outsider a foothold inside the helpdesk application and whatever customer, ticket, and credential data it touches.
CVE-2026-102490 is the second link: once an attacker has any code-execution foothold as the zammad local user, this flaw lets them escalate straight to root on the host. Root access on a helpdesk server is rarely the end goal — it is a pivot point into the rest of the network, which is consistent with how DIVD describes the intrusion into its own systems: from an initial foothold to full administrative control, with DIVD saying its network segmentation is what kept the attacker from spreading further into the organization's broader infrastructure.
This two-step pattern — a remotely triggerable foothold bug paired with a local privilege-escalation bug — is a familiar shape in "patch now" advisories; see Pandromeda's earlier coverage of the Cisco ISE and email gateway zero-days for a similar chain pattern, or the Citrix NetScaler SAML zero-day for another case where a single authentication-layer bug opened the door to much deeper compromise.
The AI-agent claim — DIVD's framing, not an independently confirmed fact
The detail that has drawn the most attention is DIVD's own characterization that the intrusion into its network looked like the work of an autonomous AI agent rather than a human operator working a keyboard. In its public statement, DIVD said the attack's modus operandi pointed to an "agentic AI powered" operation — an assessment DIVD itself describes as inference from observed behavior during an investigation it says is still ongoing, not a confirmed technical attribution to any specific actor, tool, or AI model.
It is important to be precise about what is and is not established here. DIVD's own newsroom post does not name a model, vendor, or confirmed attacker identity, and DIVD explicitly said it could not yet rule things out while forensics continued. Neither Zammad's advisory nor CISA's KEV catalog entry makes any claim about AI involvement — those are purely technical, vulnerability-focused documents. The "AI-driven attack" framing is DIVD's own characterization of what it observed inside its own network, and readers should treat it as DIVD's claim about DIVD's incident, not as an independently verified fact about how the Zammad flaws work or who is behind the attack.
Zammad's advisory: a narrower picture than the breach headlines suggest
Zammad published its own advisory for both CVEs, and it tells a more contained story than the breach narrative alone implies — while also leaving a real gap unresolved. On CVE-2026-102489, Zammad is direct: "Exploitation is only possible on Zammad 6.5 and earlier versions due to the runtime environment used by these versions," and it adds that "Zammad 7.0 and later are not affected in practice." Zammad says the code pattern technically exists through 7.1.3, but states that DIVD's own case notes agree the newer runtime environment prevents exploitation there. Out of additional caution, Zammad still shipped a hardening change in version 7.2.0 that removes the affected code path entirely. Versions 6.5 and earlier are already out of Zammad's support window and receive no further security updates — which, in practice, is Zammad's core argument for why admins on old versions need to move, not patch.
CVE-2026-102490 is where the vendor and the researcher are furthest apart, and Zammad has not resolved it. Zammad confirms it is "a local privilege escalation vulnerability that cannot be exploited remotely on its own" and says it has received DIVD's technical details and is "analyzing the issue as a high-priority item." Notably, Zammad links the underlying cause to packager.io, a third-party packaging and distribution service used to build and ship some Zammad installations — Zammad says packager.io has a "confirmed vulnerability" and that Zammad's team is "working on a solution" with that dependency in mind. As of this writing, there is no released fix for CVE-2026-102490, and Zammad has not confirmed the full version range DIVD associated with it. Zammad's advisory also flags a process complaint: it says information about the CVE became public before Zammad itself received the technical detail needed to reproduce and evaluate it — a disclosure-sequencing disagreement that sits alongside the version-scope disagreement, rather than a dispute over whether the bug is real.
Put plainly: the vendor and the discovering researcher agree these are serious, real vulnerabilities and agree on the broad mechanics. They disagree on how many current installations are actually exploitable today, and on whether disclosure moved at the right pace. This article is not going to flatten that into a single number — treat the version-scope question as unsettled until Zammad ships and documents a fix for CVE-2026-102490.
Why the severity score depends on who you ask
Readers will see different CVSS numbers attached to these CVEs depending on the source, and that is worth explaining rather than picking one figure as definitive. NVD's own record for both CVEs carries a primary CVSS 3.1 score of 9.8 (Critical), using the standard network-vector, no-privileges, no-interaction scoring model. The same NVD record also carries a secondary CVSS 4.0 score of 9.4 (Critical), submitted by DIVD's CSIRT team under its role as the assigning CNA — a newer scoring standard that accounts differently for factors like attack requirements and exploit maturity (DIVD's submission flags both CVEs as "ATTACKED," reflecting the real-world exploitation). Both scores land in Critical territory, so the practical urgency is the same either way; the numeric gap simply reflects two different scoring frameworks being applied by two different parties, not a factual dispute about severity.
The CISA KEV listing and what it means for federal agencies
CISA's Known Exploited Vulnerabilities catalog exists specifically to flag flaws it has confirmed are being actively exploited, with binding remediation deadlines for U.S. federal civilian executive branch (FCEB) agencies. CISA added "Zammad GmbH Zammad Session Fixation Vulnerability" (CVE-2026-102489) and "Zammad GmbH Zammad Improper Privilege Management Vulnerability" (CVE-2026-102490) to the catalog on October 2, 2026, with a remediation due date of October 5, 2026 — an unusually tight three-day window that signals how seriously CISA weighed active exploitation evidence. CISA's required action is to apply vendor mitigations following its Binding Operational Directive 26-04 guidance, including forensic triage, and to take the product offline if no mitigation is available. Although the KEV catalog's binding deadlines apply only to FCEB agencies, CISA consistently recommends all organizations — public and private — treat KEV entries as a signal to prioritize patching immediately, and the catalog's note that these two CVEs can be chained together is itself a reason to treat them as more urgent than either flaw alone.
Who is affected
- Self-hosted Zammad instances on version 6.5 or earlier are the clearest exposure for CVE-2026-102489, per Zammad's own advisory, and these versions no longer receive security updates at all.
- Any self-hosted Zammad instance, regardless of version, is a candidate for CVE-2026-102490 exposure until Zammad ships a fix — Zammad has not yet confirmed which versions are clear of it.
- Zammad Cloud customers are not addressed explicitly in Zammad's advisory; organizations on the managed cloud offering should confirm directly with Zammad support whether cloud infrastructure required any action.
- Anyone who can already run code as the local
zammaduser — including through unrelated means — has a path to root via CVE-2026-102490 until it is fixed, which raises the stakes for any other Zammad-adjacent vulnerability or misconfiguration.
For context on how quickly "patch now" advisories can escalate once a KEV listing lands, see Pandromeda's coverage of the Atlassian file-read flaw and the FortiMail zero-day, both of which followed a similar trajectory from vendor disclosure to active-exploitation confirmation.
What to do next
- Inventory every Zammad instance you run, self-hosted or otherwise, and note its exact version number. You cannot assess exposure to CVE-2026-102489 without knowing whether you're on 6.5-or-earlier, the 7.0–7.1.3 range, or 7.2.0+.
- If you're on Zammad 6.5 or earlier, treat this as urgent. Zammad's own advisory says these versions are out of support and exploitation is confirmed possible. Upgrade to a supported, patched release — Zammad recommends updating immediately.
- Update to 7.2.0 or later where possible to pick up the CVE-2026-102489 hardening fix, even if your current version is in the range Zammad considers not practically exploitable.
- Restrict access to the underlying server running Zammad to trusted administrators only — Zammad's stated mitigation for CVE-2026-102490 while no fix exists, since that flaw requires an attacker to already have some foothold on the box.
- Watch for a Zammad fix for CVE-2026-102490 and for any update tied to the referenced packager.io issue; there is no patch for this flaw as of this writing.
- If you suspect compromise, CISA's KEV entry requires forensic triage as part of remediation — don't assume a clean reboot or update alone addresses an active intrusion; review logs for session anomalies and unexpected privilege changes on the host.
- Report issues to Zammad directly at [email protected] (PGP available) if you find anything during your own review, and check Zammad's advisory page periodically for updates on the CVE-2026-102490 fix timeline.
Frequently asked questions
What is CVE-2026-102489?
It is a session fixation vulnerability in Zammad that lets an attacker hijack a session and execute code as the local zammad user. Zammad's own advisory says it is only exploitable in practice on Zammad 6.5 and earlier; a hardening fix shipped in version 7.2.0. NVD scores it CVSS 3.1 9.8; DIVD, as the assigning CNA, separately scores it CVSS 4.0 9.4.
What is CVE-2026-102490?
It is a local privilege escalation flaw that lets the zammad user escalate to root. It cannot be exploited remotely on its own, but can be chained after CVE-2026-102489. Zammad has not yet released a fix and says the issue is linked to a confirmed vulnerability in the third-party tool packager.io.
Which Zammad versions are affected?
Zammad's advisory says CVE-2026-102489 is exploitable only on 6.5 and earlier, with 7.0 and later not affected in practice despite containing the same code through 7.1.3. For CVE-2026-102490, Zammad has not confirmed an affected version range and is still analyzing it, so administrators on any version should take precautions.
Did an AI agent really carry out the attack on DIVD?
That is DIVD's own characterization, not an independently confirmed fact. DIVD said the attack's modus operandi pointed to an agentic AI-powered operation, based on its observation of the intrusion into its own network, but it has not named a specific actor, tool, or model, and its investigation was still ongoing when it made that statement.
Is there a patch for CVE-2026-102490 yet?
No. As of Zammad's advisory, the company says it is analyzing the issue as a high-priority item and working on a fix tied to a related packager.io vulnerability. Until a patch ships, Zammad recommends restricting access to the underlying server to trusted administrators.
Were both CVEs added to CISA's KEV catalog?
Yes. CISA added CVE-2026-102489 and CVE-2026-102490 to its Known Exploited Vulnerabilities catalog on October 2, 2026, with an October 5, 2026 remediation due date for federal civilian agencies, and noted the two flaws can be chained together.
Sources
- Zammad Security Advisory: CVE-2026-102489 & CVE-2026-102490zammad.com
- CISA Known Exploited Vulnerabilities Catalogcisa.gov
- NVD: CVE-2026-102489nvd.nist.gov
- NVD: CVE-2026-102490nvd.nist.gov
- DIVD Newsroom: "It was a matter of when, not if..."divd.nl
Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.


