U .S. CISA has added two Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog. The vulnerabilities are CVE-2026-102489 (session fixation) and CVE-2026-102490 (improper privilege management), each with a CVSS of 9.4. CVE-2026-102489 affects Zammad versions 6.3.0–6.5.4 and 7.0.0–7.1.3, while CVE-2026-102490 affects 1.5.0–7.1.0-alpha.
The two flaws can be chained: an attacker can obtain code execution as the zammad user via CVE-2026-102489 and then escalate to root through CVE-2026-102490, enabling rapid lateral movement and privilege uplift.
The disclosure follows findings from the Dutch Institute for Vulnerability Disclosure (DIVD), which reported two previously unknown Zammad flaws used in an attack targeting its own ticketing system. DIVD, working with Merlon Security, noted the attacker used an AI agent to chain the exploits and move from unauthenticated access to root within seconds, accessing other services and exfiltrating data before DIVD could fully contain the breach.
Zammad customers—more than 2,000 organisations and 55,000 users—are advised to update to version 7 or take affected systems offline immediately. DIVD published a case file and a script to check logs for signs of abuse. CISA requires federal agencies to mitigate KEVs by 5 October 2026 under BOD 22‑01, with private organisations urged to review the KEV catalog and patch accordingly.