Thank you for reading or listening to The Realist Juggernaut. Independent journalism should be accessible to everyone.
THREAT SUMMARY
Category: Actively Exploited Vulnerabilities / Zammad / Session Security / Privilege Management / Remote Code Execution
Affected Product(s): Zammad
CVE(s): CVE-2026-102489, CVE-2026-102490
Primary Risks: Session compromise, remote code execution under the Zammad service account, local privilege escalation to root, unauthorized system access, data exposure, and potential complete host compromise when the vulnerabilities are successfully chained
Threat Status: Active exploitation confirmed by CISA
Affected Environment(s): Zammad deployments on Linux and Docker within the affected version ranges documented by DIVD
Attack Vector(s): CVE-2026-102489 is network reachable under documented affected conditions; CVE-2026-102490 requires local access as the Zammad user but can be chained after initial compromise
CVSS: CVE-2026-102489 — 8.7 HIGH; CVE-2026-102490 — 8.5 HIGH; documented chained scenario — 9.4 CRITICAL
CISA Action: Both vulnerabilities added to the Known Exploited Vulnerabilities Catalog on October 2, 2026
Required Response: Federal Civilian Executive Branch agencies must apply BOD 26-04 risk-based remediation requirements. All organizations operating affected Zammad deployments should prioritize patching, exposure review, and compromise assessment.
CISA has added two vulnerabilities affecting Zammad to its Known Exploited Vulnerabilities Catalog after determining that both are being actively exploited.
The October 2 additions are CVE-2026-102489, which CISA classifies as a Zammad session fixation vulnerability, and CVE-2026-102490, identified as an improper privilege management vulnerability.
The pair presents a more serious operational concern when examined together.
Technical analysis published by the Dutch Institute for Vulnerability Disclosure states that CVE-2026-102489 can produce remote code execution under affected Zammad conditions and that CVE-2026-102490 can allow the local Zammad service user to escalate privileges to root. DIVD documented a chained scenario with a CVSS 4.0 score of 9.4 CRITICAL, combining network access, code execution, and privilege escalation.
This is no longer a theoretical vulnerability-management issue. CISA has placed both flaws in KEV based on evidence of active exploitation, and DIVD has separately reported that the two zero-day vulnerabilities were used together during the September 21 intrusion into its systems.
Vulnerability Details
CVE-2026-102489 — Zammad Session Fixation Vulnerability
CISA identifies CVE-2026-102489 as a session fixation vulnerability affecting Zammad.
DIVD’s technical disclosure describes the flaw as capable of remote code execution in affected Zammad versions, with the resulting execution occurring as the Zammad service user. The organization also reports that the vulnerability can be used in connection with session leakage.
DIVD assigns the vulnerability a CVSS 4.0 base score of 8.7 HIGH. The published scoring describes a network attack vector, low attack complexity, no additional attack requirements, and no privileges required in the documented general scenario.
The affected-version picture requires precision.
DIVD reports that Zammad 6.3.0 through versions before 6.5.4 is vulnerable to the remote-code-execution condition. The organization states that the vulnerability is also present in Zammad 7.0.0 through 7.1.3, but is not exploitable there under the documented environmental conditions.
That does not mean operators of version 7 should ignore the issue. Version presence, exploitability, environmental controls, and patch status must be evaluated separately.
CVE-2026-102490 — Zammad Improper Privilege Management Vulnerability
CISA identifies CVE-2026-102490 as an improper privilege management vulnerability.
DIVD describes the technical consequence more specifically: a local Zammad user can escalate privileges to root. The affected range published by DIVD covers Zammad from version 1.5.0 up to versions before 7.1.0-alpha across Linux and Docker environments.
The vulnerability carries a CVSS 4.0 score of 8.5 HIGH in the general scenario.
Its standalone attack vector is local rather than remote, which means an attacker must first obtain the required local execution context. That limitation becomes substantially less reassuring when another vulnerability can provide the initial code execution.
This is where the relationship between the two KEV entries becomes critical.
The Chained Attack Path
DIVD has documented that CVE-2026-102489 and CVE-2026-102490 can be combined into a chained attack path.
Under the documented scenario, the first vulnerability can provide remote access and code execution as the Zammad user. The second vulnerability can then elevate that local Zammad context to root privileges.
DIVD assigns that combined scenario a CVSS score of 9.4 CRITICAL.
The organization also reported that attackers used two Zammad zero-day vulnerabilities during a September 21 compromise of DIVD systems. DIVD stated that the chain allowed session hijacking, remote code execution, and privilege escalation from the Zammad user to root.
That incident gives defenders an important operational lesson.
A vulnerability that appears limited when examined independently can become significantly more dangerous when paired with another weakness that supplies the missing level of access.
CVE-2026-102490 is a local privilege-escalation flaw by itself. Once an attacker obtains execution as the Zammad user through another vulnerability, the local-access requirement becomes part of an attack chain rather than a meaningful barrier.
Affected Zammad Versions
Available technical information identifies different exposure ranges for the two vulnerabilities.
For CVE-2026-102489, DIVD reports exploitable remote code execution affecting Zammad 6.3.0 through versions before 6.5.4. The flaw is also reported as present in 7.0.0 through 7.1.3, though DIVD states that environmental conditions prevent exploitation in those versions under the documented scenario.
For CVE-2026-102490, DIVD identifies affected Zammad versions beginning with 1.5.0 and extending to versions before 7.1.0-alpha.
Zammad’s own security policy states that security fixes are provided for the current stable release and that older versions must be upgraded before security issues are addressed. Zammad also has a history of directing self-hosted customers to update promptly when security releases are issued.
DIVD recommends upgrading affected deployments to Zammad version 7 or taking vulnerable systems offline where remediation cannot be completed immediately.
Operational Impact
These vulnerabilities deserve attention because Zammad functions as a customer-support and ticket-management platform that can contain user information, support records, internal communications, attachments, authentication data, and administrative workflows.
Successful exploitation of CVE-2026-102489 under affected conditions can provide execution within the Zammad application context.
Successful exploitation of CVE-2026-102490 can elevate the local Zammad user to root.
When chained, the attacker can move from a remotely reachable application vulnerability to privileged control of the underlying host under the scenario documented by DIVD.
That can shift the security problem beyond the helpdesk application itself.
A root-level compromise can require defenders to evaluate the operating system, application data, stored credentials, authentication material, connected services, administrative changes, persistence mechanisms, and surrounding infrastructure rather than treating the incident as a simple application patching event.
Why KEV Status Matters
CISA does not add vulnerabilities to the KEV Catalog solely because they are severe on paper.
KEV inclusion requires evidence that exploitation has occurred.
That changes the remediation calculation.
Security teams often manage hundreds or thousands of identified vulnerabilities at the same time. A high CVSS score can indicate technical severity, but KEV status adds evidence that attackers are actually using the flaw.
CVE-2026-102489 and CVE-2026-102490 now carry both characteristics: significant technical impact and confirmed exploitation.
The combined attack path makes prioritization more urgent because the two flaws can remove different layers of protection within the same intrusion sequence.
Federal Response
The October 2 additions fall under Binding Operational Directive 26-04: Prioritizing Security Updates Based on Risk.
BOD 26-04 establishes vulnerability-management requirements for Federal Civilian Executive Branch agencies and places particular emphasis on KEV vulnerabilities affecting publicly exposed assets where exploitation can produce total control.
The directive also establishes expectations for determining when agencies must investigate whether systems were compromised before remediation occurred.
That requirement is particularly relevant here.
Patching a vulnerable Zammad deployment closes the known software weakness, but it does not establish whether an attacker already obtained access while the system remained vulnerable.
For systems exposed during the known exploitation window, remediation and compromise assessment should be treated as separate security tasks.
CISA encourages private organizations, state and local governments, educational institutions, nonprofits, and other entities outside the FCEB environment to use the KEV Catalog as a risk-based remediation priority list.
Defensive Guidance
Organizations operating Zammad should first identify every deployment and determine the exact version, hosting model, exposure status, and remediation state.
Priority actions should include:
- Inventory all Zammad systems across production, testing, development, backup, and disaster-recovery environments.
- Identify installations running versions associated with CVE-2026-102489 or CVE-2026-102490.
- Upgrade affected systems to a supported and remediated Zammad release.
- Remove vulnerable systems from public exposure when immediate remediation cannot be completed.
- Review Linux and Docker-hosted Zammad environments separately where applicable.
- Examine authentication and session activity for unexplained behavior.
- Review administrative accounts and privilege changes.
- Inspect the underlying operating system for unauthorized root-level activity.
- Review application logs, web logs, authentication records, and system logs.
- Examine recently created users, services, scheduled tasks, persistence mechanisms, and configuration changes.
- Review outbound connections from the Zammad host.
- Rotate sensitive credentials if compromise is suspected.
- Preserve forensic evidence before rebuilding or materially altering a suspected compromised system.
- Validate segmentation between Zammad infrastructure and other internal systems.
Organizations should also determine whether Zammad systems have access to directory services, email infrastructure, APIs, databases, identity providers, ticket attachments, or other internal resources.
A compromised application server can become a pivot point when trust relationships extend beyond the application itself.
Compromise Assessment
Because active exploitation has been confirmed, affected organizations should not assume that installing an update closes the entire incident.
A compromise assessment should determine whether exploitation occurred before remediation.
Areas requiring examination can include abnormal user sessions, unauthorized administrative activity, unexpected execution under the Zammad service account, unexplained root activity, new system users, unfamiliar SSH keys, modified startup services, scheduled jobs, changes to application files, unusual outbound network traffic, altered authentication settings, and access to systems that normally should not communicate with the Zammad host.
Defenders should also examine whether attackers accessed ticket content, attachments, user records, credentials, API keys, email integration settings, or other information available through the application or its host.
These are investigative areas based on the documented capabilities of the vulnerability chain and should not be treated as CISA-issued indicators of compromise.
DIVD’s own incident demonstrates why this review matters. The organization reported that attackers chained the two vulnerabilities, obtained root-level access, reached other services, and exfiltrated data before containment measures stopped deeper movement through the environment.
Zero-Day Context
The two vulnerabilities were not first discovered as routine patch-management findings.
DIVD reports that the vulnerabilities were identified during investigation of a September compromise involving its own systems. The organization says the flaws were analyzed and reproduced after malicious activity was detected, reported to Zammad, assigned CVE identifiers, and followed by scanning and notification efforts directed at potentially vulnerable systems.
DIVD began scanning for publicly vulnerable Zammad instances on September 26 and started notifying affected owners.
That sequence illustrates one of the difficult realities of zero-day response: exploitation can occur before defenders have a CVE number, vendor advisory, or established patching routine available.
By the time CISA added the vulnerabilities to KEV on October 2, exploitation was already documented.
30-Day Outlook
CVE-2026-102489 and CVE-2026-102490 are likely to remain high-priority remediation issues during the immediate response period because public disclosure now provides defenders and attackers with greater awareness of the affected product, version ranges, and attack relationship.
Organizations that have not maintained accurate Zammad inventories face a greater risk of leaving vulnerable systems behind.
Legacy self-hosted instances, test environments, abandoned deployments, externally exposed support systems, and secondary Docker installations warrant particular attention.
Security teams should also expect continuing technical clarification as Zammad, CISA, DIVD, and vulnerability coordinators refine affected-version information, remediation guidance, and exploitation details.
The core facts are already strong enough to act on: both vulnerabilities are in CISA’s KEV Catalog, active exploitation has been confirmed, and independent incident analysis has documented the two flaws operating as a chain.
TRJ Verdict
CVE-2026-102489 and CVE-2026-102490 demonstrate why vulnerability severity cannot always be evaluated one flaw at a time.
One vulnerability can provide the initial foothold. The other can remove the privilege boundary protecting the host.
Together, DIVD has documented a path from remote exploitation to execution as the Zammad user and then to root-level control, producing a 9.4 CRITICAL chained scenario.
CISA’s October 2 KEV additions confirm that these vulnerabilities have moved beyond laboratory analysis into active exploitation.
Organizations operating Zammad should identify affected installations, upgrade supported systems, remove unresolved vulnerable deployments from exposure, review systems for evidence of compromise, and treat unexplained activity as an incident requiring investigation rather than assuming patch installation alone resolves prior exposure.
For defenders, the central warning is straightforward:
The danger is not only that two Zammad vulnerabilities exist. It is that attackers have already demonstrated what can happen when they are used together.
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



