CVE-2026-102489: Zammad zero-day chain, KEV due 5 October
Session hijack to root on internet-facing Zammad helpdesks

CVE-2026-102489: Zammad zero-day chain, KEV due 5 October

CISA added CVE-2026-102489 and CVE-2026-102490 to the Known Exploited Vulnerabilities catalog on 2 October 2026. The federal due date is 5 October. The Dutch Institute for Vulnerability Disclosure says the pair was used as a zero-day chain against its own Zammad helpdesk on 21 September.

What happened

DIVD describes CVE-2026-102489 as a session-hijack flaw that leads to remote code execution as the zammad user, and CVE-2026-102490 as a local privilege escalation to root. Chained, the attacker moved from a hijacked session to code execution to root in seconds. DIVD says the speed and the messy next-step logic point to an agentic AI-driven attack. Network segmentation stopped a deeper pivot, but the institute is assuming breach until proven otherwise.

This is a disputed disclosure. Zammad GmbH has disagreed with DIVD on affected versions and on how the report was handled. NVD still lists both as critical, and CISA is treating both as exploited. DIVD says a verification script is available from its case page.

Who is affected

  • DIVD says Zammad 6.3.0 through 6.5.4 is exploitable for the session-hijack bug. Versions 7.0.0 through 7.1.3 contain the defect but are not exploitable because of environment conditions.
  • CISA says the privilege-escalation bug can be chained with the session bug and that the local zammad user can reach root.
  • Internet-facing support portals are the exposed set. Internal-only instances are a lower priority, not a free pass.

What to do now

Take public Zammad offline or upgrade to version 7, then hunt for unexpected root activity from the zammad user. DIVD's own advice is to upgrade to version 7 or disconnect the service. A vendor GitHub security advisory was not published as of this writing, so do not wait on a tidy patch note if the portal is on the internet. Check for new shells, odd cron entries, and outbound connections from the Zammad host dated on or after 21 September.

Source: SecurityWeek, Zammad zero-days exploited in AI-powered DIVD hack. DIVD case: DIVD-2026-00015.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

CVE-2026-104286: FortiMail path traversal, no patch yet
Unauthenticated arbitrary file write on FortiMail with IBE enabled