Cyber & AI intelligence
Wasteland.
Briefs indexed2982
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-102489 2026-10-02

Zammad Session Fixation Flaw CVE-2026-102489 Exploited, Can Lead to Remote Code Execution

"CISA has added CVE-2026-102489 to its Known Exploited Vulnerabilities (KEV) catalog. It is a critical session fixation flaw in the Zammad helpdesk platform. According to NVD, it can lead to remote code execution as the…"

CISA has added CVE-2026-102489 to its Known Exploited Vulnerabilities (KEV) catalog. It is a critical session fixation flaw in the Zammad helpdesk platform. According to NVD, it can lead to remote code execution as the zammad user. Federal agencies have until October 5, 2026 to address it.

What Is It

CVE-2026-102489 is a session fixation weakness (CWE-384) in Zammad, made by Zammad GmbH. NVD describes it as a session hijack issue that can lead to remote code execution as the zammad user. CISA says it can be chained with CVE-2026-102490. One of CISA's reference links is a Zammad community thread whose title describes CVE-2026-102490 as an actively exploited local privilege escalation.

The vulnerability was reported through DIVD CSIRT and published to NVD on September 30, 2026.

Why It Matters

CISA added the flaw to KEV on October 2, 2026, which confirms active exploitation. The available sources do not say what attackers have achieved in observed attacks, including whether any exploitation has resulted in code execution. CISA's SSVC assessment rates exploitation as "active," automatable as "yes," and technical impact as "total."

KEV lists ransomware use as "Unknown." CISA has flagged the entry for forensic triage ("Forensic Triage: Yes"), so organizations should look for signs of compromise, not just patch.

What's Vulnerable

Patch Status

CISA's required action: apply mitigations according to vendor instructions, following BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements. For cloud services, follow the applicable BOD 26-04 guidance. If mitigations aren't available, stop using the product. Organizations are responsible for checking each asset's internet exposure.

The federal remediation due date is October 5, 2026. The source data doesn't name a specific fixed release. Check Zammad's release page and the DIVD advisories for upgrade guidance. Teams running 6.x should also review exposure to the chained CVE-2026-102490.

Sources