# CISA Flags Two Zammad Vulnerabilities as Exploited

Published: 2026-10-02 · Severity: severe · Sectors: government-national
Canonical: https://vorant.io/reports/c3269b7d-1475-56e9-9496-524f3a83f719/cisa-flags-two-zammad-vulnerabilities-as-exploited

> CISA added two actively exploited Zammad vulnerabilities—session fixation and improper privilege management—to its Known Exploited Vulnerabilities catalog.

CISA has added two vulnerabilities affecting Zammad GmbH's helpdesk software to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-102489 is a session fixation vulnerability, while CVE-2026-102490 involves improper privilege management. Session fixation flaws typically allow attackers to hijack authenticated sessions by forcing a victim to use a known session identifier, while improper privilege management can enable unauthorized escalation of access within the application.

Under Binding Operational Directive (BOD 26-04), Federal Civilian Executive Branch (FCEB) agencies are required to prioritize remediation of KEV-listed vulnerabilities on publicly exposed assets, particularly those granting total control post-exploitation, and to check for prior compromise before patching. Although BOD 26-04 only binds federal agencies, CISA recommends all organizations using Zammad treat these as high-priority patches given confirmed in-the-wild exploitation.

Defenders running Zammad instances should identify affected versions, apply vendor patches or mitigations as soon as available, and review authentication logs for signs of session hijacking or unauthorized privilege changes. No technical exploitation details, affected version ranges, or IOCs were provided in this bulletin; organizations should consult Zammad's security advisories for patch information.

## Mentioned in this report

- Vulnerabilities: CVE-2026-102489 (KEV), CVE-2026-102490 (KEV)

Source reporting: https://www.cisa.gov/news-events/alerts/2026/10/02/cisa-adds-two-known-exploited-vulnerabilities-catalog

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/c3269b7d-1475-56e9-9496-524f3a83f719/cisa-flags-two-zammad-vulnerabilities-as-exploited.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
