CISA adds two Zammad flaws to Known Exploited Vulnerabilities catalog
CISA added two Zammad vulnerabilities with a CVSS score of 9.4 to its Known Exploited Vulnerabilities catalog: CVE-2026-102489 (session fixation leading to RCE as the zammad user) and CVE-2026-102490 (local privilege escalation to root). Chained, they let an attacker go from session hijacking to root in seconds. Federal agencies must remediate by October 5, 2026.
- CVE-2026-102489: CVSS 9.4, RCE as the zammad user, affects versions 6.3.0–6.5.4 and 7.0.0–7.1.3
- CVE-2026-102490: CVSS 9.4, privilege escalation to root, affects versions 1.5.0–7.1.0-alpha
- Chaining both flaws gives root in seconds; an AI agent drove the DIVD attack
- CISA orders federal agencies to fix the flaws by October 5, 2026
Read next
Security