CISA has added CVE-2026-102489 to its Known Exploited Vulnerabilities (KEV) catalog. It is a critical session fixation flaw in the Zammad helpdesk platform. According to NVD, it can lead to remote code execution as the zammad user. Federal agencies have until October 5, 2026 to address it.
What Is It
CVE-2026-102489 is a session fixation weakness (CWE-384) in Zammad, made by Zammad GmbH. NVD describes it as a session hijack issue that can lead to remote code execution as the zammad user. CISA says it can be chained with CVE-2026-102490. One of CISA's reference links is a Zammad community thread whose title describes CVE-2026-102490 as an actively exploited local privilege escalation.
The vulnerability was reported through DIVD CSIRT and published to NVD on September 30, 2026.
Why It Matters
CISA added the flaw to KEV on October 2, 2026, which confirms active exploitation. The available sources do not say what attackers have achieved in observed attacks, including whether any exploitation has resulted in code execution. CISA's SSVC assessment rates exploitation as "active," automatable as "yes," and technical impact as "total."
- NVD CVSS 3.1: 9.8 Critical (
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The attack works over the network, is low complexity, and needs no privileges. - DIVD CVSS 4.0: 9.4 Critical. This score assumes passive user interaction and marks exploit maturity as "Attacked."
KEV lists ransomware use as "Unknown." CISA has flagged the entry for forensic triage ("Forensic Triage: Yes"), so organizations should look for signs of compromise, not just patch.
What's Vulnerable
- Affected: Zammad 6.3.0 up to 6.5.4. DIVD's affected-version data marks 6.5.4 as the upper limit, but the NVD description reads "6.3.0 to 6.5.4."
- Present but not exploitable: Zammad 7.0.0 through 7.1.3. NVD says the flaw exists in these versions but can't be exploited because of environment conditions. NVD's CPE configuration lists this range as vulnerable, while DIVD marks 7.0.0 and later as unaffected.
- Unknown: versions earlier than 6.3.0.
- Platforms: Linux and Docker deployments.
Patch Status
CISA's required action: apply mitigations according to vendor instructions, following BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements. For cloud services, follow the applicable BOD 26-04 guidance. If mitigations aren't available, stop using the product. Organizations are responsible for checking each asset's internet exposure.
The federal remediation due date is October 5, 2026. The source data doesn't name a specific fixed release. Check Zammad's release page and the DIVD advisories for upgrade guidance. Teams running 6.x should also review exposure to the chained CVE-2026-102490.