ATTACKERS chained two Zammad zero-day flaws to gain access to the Dutch Institute for Vulnerability Disclosure (DIVD) on 21 September 2026, exploiting CVE-2026-102489 and CVE-2026-102490. The chain enabled session hijacking that leads to remote code execution, followed by local privilege escalation to root.
In DIVD’s incident record DIVD-2026-00014, the attackers achieved “session hijacking, remote code execution and privilege escalation from the Zammad user to root” and the exploits are described as known exploited vulnerabilities. DIVD notes the attacks were automated and capable of moving from unauthenticated network access to full control in seconds.
Affected versions and practical response: CVE-2026-102489 affects Zammad 6.3.0 to 6.5.4, and also versions 7.0.0 to 7.1.3 (though DIVD indicates it is not exploitable in some environments). CVE-2026-102490 affects Zammad 1.5.0 up to 7.1.0 alpha. Both flaws are exploitable across Linux and Docker deployments and are rated with CVSSv4 scores around 9.4.
The recommended immediate action is to upgrade to Zammad version 6.5.4, 7.0.0 or 7.1.0-alpha, or take the system offline until patched, as the DIVD assessment labels these as “known exploited vulnerabilities.” DIVD also advises scans for indicators of compromise, restricting internet access to Zammad (e.g., via VPN), rotating credentials, and network segmentation to limit further damage. Evidence of exploitation comes from DIVD’s incident briefing and the organisation’s ongoing monitoring of exposed Zammad instances.