← Back to feed
Vulnerabilities & PatchesEmerging1 sourceOct 2, 2026 · 22:46via Security Affairs

U.S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog

Brief

U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog.

The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog :

  • CVE-2026-102489 (CVSS score of 9.4) Zammad GmbH Zammad Session Fixation Vulnerability
  • CVE-2026-102490 (CVSS score of 9.4) Zammad GmbH Zammad Improper Privilege Management Vulnerability

The first flaw, CVE-2026-102489, is a session hijacking vulnerability in Zammad that can lead to remote code execution as the zammad user. It affects Zammad 6.

  • 0 through 6.
  • 4. The flaw is also present in versions 7.
  • 0 through 7.
  • 3.

The second flaw, CVE-2026-102490, is a local privilege escalation vulnerability that allows the zammad user to gain root privileges.

Read more on Security Affairs→