// 2 CRITICAL · 2 ZERO-DAY · 3 CVE · 4 EXPLOIT · 1 ADVISORY IN THE LAST 24H→
CISA added two zero-day vulnerabilities in Zammad to its Known Exploited Vulnerabilities catalog, both rated CVSS 9.4. Federal Civilian Executive Branch agencies must patch by Oct. 5, 2026, per Binding Operational Directive 26-04. The flaws form an exploit chain discovered during the Dutch Institute for Vulnerability Disclosure's (DIVD) incident response after its own ticketing system was compromised.

On Oct. 2, 2026, CISA added two zero-day vulnerabilities in Zammad GmbH Zammad, the open-source ticketing system, to its Known Exploited Vulnerabilities (KEV) catalog. U.S. Federal Civilian Executive Branch (FCEB) agencies have until Oct. 5, 2026, to apply patches under Binding Operational Directive 26-04. The discovery occurred under striking circumstances: the flaws surfaced during the Dutch Institute for Vulnerability Disclosure's (DIVD) incident response after its own ticketing system was breached.

Key Takeaways
  • CVE-2026-102489 (session fixation leading to RCE as the zammad user) and CVE-2026-102490 (improper privilege management enabling escalation to root) are both in the CISA KEV with a deadline of Oct. 5, 2026
  • The two vulnerabilities form an exploit chain enabling full system compromise
  • Discovery occurred during DIVD's incident response following a breach of its own Zammad instance
  • CVE.org lists two distinct CVSS 4.0 scores for CVE-2026-102489 (8.7 HIGH and 9.4 CRITICAL) with different vectors, while Security Affairs reports 9.4 for both CVEs

The Exploit Chain: From Session Hijack to Root

The first vulnerability, CVE-2026-102489, is a session fixation flaw that CISA describes in the KEV as enabling remote code execution with the privileges of the zammad service user. The CVE.org record classifies it as a session hijack vulnerability with remote code execution. The second, CVE-2026-102490, is an improper privilege management vulnerability allowing the local zammad user to escalate privileges to root.

CISA explicitly documented the chainability of the two flaws: both KEV entries note they can be chained with the other CVE. This attack architecture is particularly efficient because it leverages an initial remote compromise to then elevate privileges at the operating system level, achieving complete control of the target machine.

CVSS Scoring: A System in Transition

Risk assessment carries added complexity due to the transition to CVSS 4.0. According to Security Affairs, both vulnerabilities score 9.4. The official CVE.org record for CVE-2026-102489 shows two distinct scores instead: 8.7 HIGH and 9.4 CRITICAL, associated with different CVSS 4.0 vectors and impact scopes. This duplication reflects the new scoring system's granularity, which distinguishes environmental and specific impact metrics, but can create uncertainty in operational prioritization.

For CVE-2026-102490, the dossier does not include a dual score on CVE.org; the source cites 9.4 via Security Affairs. The discrepancy between sources on the first identifier suggests organizations should verify official vectors directly rather than rely on aggregated summaries.

Affected Versions and Software Distribution

Affected versions follow different patterns for the two vulnerabilities. CVE-2026-102489 impacts Zammad from version 6.3.0 through 6.5.4 and versions 7.0.0 through 7.1.3, with a CVE.org annotation that 7.x versions are not exploitable due to specific environmental conditions. CVE-2026-102490 has a wider range, spanning version 1.5.0 through 7.1.0-alpha.

Zammad serves over 2,000 customers and more than 55,000 active users, according to data cited by Security Affairs. Its open-source nature and role as a ticketing system make it a critical infrastructure component for many organizations, including entities that themselves handle cybersecurity.

The DIVD Incident: When Vulnerability Hunters Get Hacked

The most notable aspect of this story is the origin of the discovery. DIVD, a Dutch institute specializing in responsible vulnerability disclosure, suffered a compromise of its own Zammad-based ticketing system. During forensic analysis of the incident, the organization identified the two zero-days behind the attack.

"When hackers get hacked, we deal with it in hacker style. While trying to figure out how the attackers got into our own systems, we found two zero-day vulnerabilities in Zammad." — DIVD, quoted by Security Affairs

DIVD collaborated with Merlon Security, specifically Tijmen van der Spijk, for technical analysis. The researcher's name appears as the finder in the CVE.org record. The Dutch organization stated that "some damage had already occurred" before discovery, without detailing the nature or extent of compromised data.

The dossier does not specify the exact date of the DIVD breach, nor the attackers' identity. Security Affairs reports DIVD had indicated a public update expected for Oct. 1, but the timeline remains partially indeterminate across sources. The element described by Security Affairs as the "agentic part of this hack" — referring to a presumed AI-based automation component — comes exclusively from a DIVD LinkedIn citation and is not independently confirmed in the dossier.

Immediate Actions

  • Update Zammad to version 7, identified by DIVD as the definitive fix for both vulnerabilities
  • Conduct forensic triage to verify any prior compromise before patching, as explicitly required by BOD 26-04 for FCEB agencies
  • Consider temporary system disconnection if immediate updating is not feasible, per DIVD's recommendation
  • Verify specific CVSS 4.0 vectors on CVE.org for your version, given the multiple scores for CVE-2026-102489

KEV Acceleration and New Triage Expectations

Inclusion in the KEV catalog with a three-day deadline from publication aligns with CISA's push to compress response times for vulnerabilities with evidence of active exploitation. BOD 26-04 mandates not only patching but adds a forensic triage requirement: agencies must demonstrate they have verified the presence or absence of prior hostile activity before mitigation. This marks a progressive formalization of the post-patch phase, which is no longer considered the end of an incident but an integral part of the remediation cycle.

The case also raises a structural question for the security sector: organizations whose operational model includes handling sensitive third-party data — vulnerabilities, reports, vendor communications — can become high-value targets precisely because of the information they hold. A ticketing system compromise is not a peripheral incident if that system archives unpublished details on flaws in third-party products.

The lack of attribution and the inability to independently verify the "AI agent" component described by DIVD leave open questions about the attack's full nature. What is documented — the exploit chain, the speed of KEV inclusion, the binding deadline — is sufficient to establish the case's severity without adding speculation.

Sources

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. securityaffairs.com
  2. cisa.gov
  3. infosectoday.io
  4. cve.org