# Zammad zero-days exploited for root RCE

Published: 2026-09-30 · Severity: high
Canonical: https://vorant.io/reports/7a3964b8-9dba-5cb6-86a6-82ba65482138/zammad-zero-days-exploited-for-root-rce

> Two actively exploited Zammad zero-days allow unauthenticated remote code execution and privilege escalation to root; only one has a patch.

NCSC-NL issued a high-priority advisory for two zero-day vulnerabilities in Zammad, an open-source helpdesk/ticketing platform. CVE-2026-102489 (CVSS v4 9.4) allows an unauthenticated remote attacker to execute arbitrary code, affecting Zammad versions 6.3.0 through 6.5.4. CVE-2026-102490 (CVSS v4 9.4) allows a low-privileged attacker to escalate to root privileges on the host running Zammad, and affects all common versions of the product. Both flaws have been actively exploited in the wild since at least 21 September 2026 to gain remote root access to systems running Zammad.

Zammad has released a security update addressing CVE-2026-102489; NCSC-NL urges affected organizations to patch urgently. CVE-2026-102490 remains unpatched at time of publication, and the advisory recommends contacting the vendor for guidance. Defenders are advised to preserve application and network logs before applying updates, as this data may be needed later to determine whether their Zammad environment was compromised during the zero-day exploitation window.

Given the combination of unauthenticated RCE, confirmed in-the-wild exploitation leading to root compromise, and an outstanding unpatched privilege-escalation flaw, organizations running Zammad should treat this as an urgent priority: patch CVE-2026-102489 immediately, review logs for signs of compromise since 21 September 2026, and monitor vendor channels for a fix to CVE-2026-102490.

## Mentioned in this report

- Vulnerabilities: CVE-2026-102489, CVE-2026-102490

## Detection guidance (public sample)

### Zammad Process Spawning Shell with Suspicious Arguments

ATT&CK: T1190

Detects Zammad application spawning shell interpreters (bash, sh, dash) with arguments indicative of command injection or code execution exploits. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Zammad Process Spawning Shell with Suspicious Arguments
description: Detects ruby or node processes (typical Zammad runtime) spawning shell
  interpreters with command-line arguments. Zammad zero-day exploits (CVE-2026-102489,
  CVE-2026-102490) achieve RCE by injecting commands through application parameters,
  resulting in shell child processes with attacker-supplied payloads.
tags:
- attack.t1190
- attack.execution
logsource:
  category: process_creation
  product: linux
detection:
  selection_parent:
    ParentImage|endswith:
    - /ruby
    - /bin/ruby
    - /node
    - /bin/node
  selection_child:
    Image|endswith:
    - /bash
    - /sh
    - /dash
  selection_args:
    CommandLine|contains:
    - ' -c '
    - $(\
    - '`'
    - '|'
    - ;
  filter_legitimate:
    CommandLine|contains:
    - npm install
    - bundle install
    - rake db
  condition: selection_parent and selection_child and selection_args and not filter_legitimate
falsepositives:
- Zammad administrative scripts or deployment automation executing shell commands
- Legitimate application maintenance tasks invoking shell interpreters
level: high
id: d62e7b49-ff49-5437-8e1b-01ad14633930
status: experimental
author: Vorant
references:
- https://advisories.ncsc.nl/2026/ncsc-2026-0396.html
```

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0396.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/7a3964b8-9dba-5cb6-86a6-82ba65482138/zammad-zero-days-exploited-for-root-rce.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
