VORANT. Threat Intelligence Research Sign in Create a free account

CISA Flags Two Zammad Vulnerabilities as Exploited

severe vulnerability government-national

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

CISA added two actively exploited Zammad vulnerabilities—session fixation and improper privilege management—to its Known Exploited Vulnerabilities catalog.

CISA has added two vulnerabilities affecting Zammad GmbH's helpdesk software to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-102489 is a session fixation vulnerability, while CVE-2026-102490 involves improper privilege management. Session fixation flaws typically allow attackers to hijack authenticated sessions by forcing a victim to use a known session identifier, while improper privilege management can enable unauthorized escalation of access within the application.

Under Binding Operational Directive (BOD 26-04), Federal Civilian Executive Branch (FCEB) agencies are required to prioritize remediation of KEV-listed vulnerabilities on publicly exposed assets, particularly those granting total control post-exploitation, and to check for prior compromise before patching. Although BOD 26-04 only binds federal agencies, CISA recommends all organizations using Zammad treat these as high-priority patches given confirmed in-the-wild exploitation.

Defenders running Zammad instances should identify affected versions, apply vendor patches or mitigations as soon as available, and review authentication logs for signs of session hijacking or unauthorized privilege changes. No technical exploitation details, affected version ranges, or IOCs were provided in this bulletin; organizations should consult Zammad's security advisories for patch information.

Mentioned in this report

Vulnerabilities CVE-2026-102489KEVCVE-2026-102490KEV

Source reporting: https://www.cisa.gov/news-events/alerts/2026/10/02/cisa-adds-two-known-exploited-vulnerabilities-catalog

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 10,655 reports from 152 sources, 505 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs