Zammad zero-days exploited for root RCE
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
Two actively exploited Zammad zero-days allow unauthenticated remote code execution and privilege escalation to root; only one has a patch.
NCSC-NL issued a high-priority advisory for two zero-day vulnerabilities in Zammad, an open-source helpdesk/ticketing platform. CVE-2026-102489 (CVSS v4 9.4) allows an unauthenticated remote attacker to execute arbitrary code, affecting Zammad versions 6.3.0 through 6.5.4. CVE-2026-102490 (CVSS v4 9.4) allows a low-privileged attacker to escalate to root privileges on the host running Zammad, and affects all common versions of the product. Both flaws have been actively exploited in the wild since at least 21 September 2026 to gain remote root access to systems running Zammad.
Zammad has released a security update addressing CVE-2026-102489; NCSC-NL urges affected organizations to patch urgently. CVE-2026-102490 remains unpatched at time of publication, and the advisory recommends contacting the vendor for guidance. Defenders are advised to preserve application and network logs before applying updates, as this data may be needed later to determine whether their Zammad environment was compromised during the zero-day exploitation window.
Given the combination of unauthenticated RCE, confirmed in-the-wild exploitation leading to root compromise, and an outstanding unpatched privilege-escalation flaw, organizations running Zammad should treat this as an urgent priority: patch CVE-2026-102489 immediately, review logs for signs of compromise since 21 September 2026, and monitor vendor channels for a fix to CVE-2026-102490.
Mentioned in this report
Detection guidance
Zammad Process Spawning Shell with Suspicious Arguments
Detects Zammad application spawning shell interpreters (bash, sh, dash) with arguments indicative of command injection or code execution exploits. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.
title: Zammad Process Spawning Shell with Suspicious Arguments
description: Detects ruby or node processes (typical Zammad runtime) spawning shell
interpreters with command-line arguments. Zammad zero-day exploits (CVE-2026-102489,
CVE-2026-102490) achieve RCE by injecting commands through application parameters,
resulting in shell child processes with attacker-supplied payloads.
tags:
- attack.t1190
- attack.execution
logsource:
category: process_creation
product: linux
detection:
selection_parent:
ParentImage|endswith:
- /ruby
- /bin/ruby
- /node
- /bin/node
selection_child:
Image|endswith:
- /bash
- /sh
- /dash
selection_args:
CommandLine|contains:
- ' -c '
- $(\
- '`'
- '|'
- ;
filter_legitimate:
CommandLine|contains:
- npm install
- bundle install
- rake db
condition: selection_parent and selection_child and selection_args and not filter_legitimate
falsepositives:
- Zammad administrative scripts or deployment automation executing shell commands
- Legitimate application maintenance tasks invoking shell interpreters
level: high
id: d62e7b49-ff49-5437-8e1b-01ad14633930
status: experimental
author: Vorant
references:
- https://advisories.ncsc.nl/2026/ncsc-2026-0396.html
Behavioural rules are generated from public reporting — validate in your environment before deploying.
Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0396.html
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 10,730 reports from 154 sources, 556 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs