Two zero-days in the open-source Zammad helpdesk and ticketing platform, CVE-2026-102489 and CVE-2026-102490, are being exploited in the wild. The Dutch Institute for Vulnerability Disclosure (DIVD) says it was breached through the chain on September 21, and that the intrusion ran at machine speed, which DIVD attributes to an autonomous AI agent. CISA added both CVEs to the Known Exploited Vulnerabilities catalog on October 2 with a federal remediation deadline of October 5.

What happened

According to DIVD’s disclosure and the press coverage that followed, attackers reached DIVD’s internal systems on September 21 by attacking its Zammad instance. DIVD found the intrusion the next day, cut access to its data center systems and brought in Merlon Security for incident response. It reported the Zammad flaws to the vendor on September 24 and notified the Dutch Data Protection Authority and the National Cyber Security Centre.

After the initial foothold, the intruder reportedly went on to password spraying, a man-in-the-middle attack and data exfiltration. DIVD has confirmed theft of volunteers’ email addresses. Its CSIRT ticketing data, Jira/Confluence and other systems are still under investigation. Network segmentation reportedly limited how far the attacker got.

Technical details

The chain has two links:

  • CVE-2026-102489 is a session hijack (session fixation) flaw. An attacker can fix or predict a session identifier and use it in an authenticated context without presenting credentials. That leads to remote code execution as the zammad OS user. It affects Zammad 6.3.0 through 6.5.4. DIVD scores it CVSS v4.0 8.7.
  • CVE-2026-102490 is a local privilege escalation from the zammad user to root. The CVE record says it affects all versions, from 1.5.0 through the current 7.1.0-alpha. Chained with the first flaw, the combined score is 9.4.

An attacker with only network access to a reachable Zammad instance can therefore go from unauthenticated to root without a password or any user interaction. DIVD reports the agent completed the session hijack, code execution and privilege escalation steps within seconds and without apparent human direction.

Impact

Helpdesk systems hold a lot of sensitive material: customer and employee correspondence, attachments, password reset and onboarding threads, and often integration credentials for LDAP, email, Jira and chat platforms. Root on the Zammad host also gives a pivot point into the internal network, as the password spraying and MitM activity at DIVD show. Any internet-facing Zammad instance should be treated as a priority target now that exploitation is confirmed and CISA has listed the CVEs.

Patch status

The patch picture is incomplete. DIVD urges operators to move to Zammad 7.x or take the instance offline. Reporting as of October 1 says upgrading to version 7 does not fix CVE-2026-102490, so the root escalation stays exploitable for anyone who already has code execution as the zammad user. Check the Zammad security advisories for a fixed build before assuming an upgrade closes the chain.

Mitigation

  1. Upgrade to Zammad 7.0.0 or later to close the session hijack and RCE entry point (CVE-2026-102489), and watch for a release that addresses CVE-2026-102490.
  2. Restrict exposure. If the instance doesn’t need to be on the internet, put it behind a VPN or an IP allowlist. Take it offline if you can’t patch.
  3. Segment. Run Zammad in its own network segment with default-deny egress and tightly scoped access to internal services. A compromised helpdesk host should not be able to reach anything else.
  4. Hunt. Look for unexpected sessions or logins, setuid-family calls, new root-owned child processes, bulk reads of credential files and config (database.yml, integration secrets), and unusual outbound uploads.
  5. Rotate secrets. If you were exposed, rotate every credential Zammad holds or can reach: database, LDAP/IMAP/SMTP, API tokens and the Rails secret key base. Invalidate all active sessions.
  6. Run a compromise assessment. For federal agencies, the CISA deadline is October 5.

References