CISA has added CVE-2026-102489 to its Known Exploited Vulnerabilities (KEV) catalogue. The vulnerability affects Zammad GmbH’s Zammad customer support platform and is known as the Zammad Session Fixation Vulnerability. It can lead to remote code execution as the zammad user and can be chained with CVE-2026-102490.
The flaw is a session fixation vulnerability. Successful exploitation can enable remote code execution under the privileges of the zammad user. Available data does not specify a more detailed attack vector. NVD assigns the vulnerability a CVSS score of 9.4, rated Critical. Patch availability is currently unknown, and no patch or advisory URL is listed in the supplied data.
CISA’s KEV listing confirms that attackers are actively exploiting this vulnerability. The available information does not confirm use in ransomware campaigns. Federal Civilian Executive Branch (FCEB) agencies must address the vulnerability by 5 October 2026.
CISA requires organisations to apply mitigations in accordance with vendor instructions and comply with its BOD 26-04 guidance on prioritising security updates based on risk, alongside the relevant Forensics Triage Requirements. For cloud services, organisations should follow applicable BOD 26-04 guidance or discontinue use of the product if mitigations are unavailable. Stakeholders must assess each asset’s internet exposure and comply with BOD 26-04 patching requirements. FCEB agencies are directly affected, but all organisations should review their exposure.
See the NVD entry for CVE-2026-102489 and CISA’s KEV catalogue for full details.