Zammad Flaws Used Against DIVD Reach CISA's Exploited List
Security / news
Zammad Flaws Used Against DIVD Reach CISA's Exploited List
The two bugs chain from an unauthenticated request to root on Linux hosts. The Dutch disclosure group found them because attackers used them on its own helpdesk on September 21.
An unauthenticated remote attacker can reach code execution as the zammad service account on Zammad 6.3.0 through 6.5.4 (CVE-2026-102489), then climb to root on any Linux or Docker install from 1.5.0 up to 7.1.0-alpha (CVE-2026-102490). CISA added both to its Known Exploited Vulnerabilities catalog on October 2.
The evidence of exploitation is unusually direct. The Dutch Institute for Vulnerability Disclosure (DIVD), the nonprofit that coordinates disclosure for other people's bugs, found the flaws after its own Zammad helpdesk was compromised.
The September 21 timeline
DIVD's case page, DIVD-2026-00015, records the sequence. The case was opened while investigating a separate breach, DIVD-2026-00014.
- September 21: the intrusion happens.
- September 22: DIVD notices it, according to Secureblink's account.
- September 24: the flaws are reported to Zammad.
- September 26: DIVD scans for exposed instances and starts notifying their owners.
- September 29: the CVE record for CVE-2026-102490 is published.
- October 2: CISA lists both CVEs.
The researchers credited on the CVE record are from Merlon Security and DIVD's CSIRT team. Patches exist, and the case was still open as of October 1.
Which Zammad versions are exposed
The version ranges are where the sources disagree, so read them carefully.
| Version range | CVE-2026-102489 | CVE-2026-102490 |
|---|---|---|
| 1.5.0 to below 6.3.0 | Not affected | Affected (Linux, Docker) |
| 6.3.0 to 6.5.4 | Exploitable | Affected |
| 7.0.0 to 7.1.3 | Present, DIVD says not exploitable | Fixed from 7.1.0-alpha |
DIVD's CVE page says 7.0.0 through 7.1.3 contain the session flaw but that environmental factors stop it being exploited. Security Affairs lists 7.0.0 through 7.1.3 as affected without that qualification. DIVD's advice is blunt: upgrade to Zammad 7 or take the instance offline. It also publishes a script that checks logs for signs of exploitation.
The score overstates each bug and understates the pair
DIVD scores CVE-2026-102489 at 8.7 on its own and CVE-2026-102490 at 8.5. Chained, it rates them 9.4.
- CVE-2026-102490 alone8.5 CVSS
- CVE-2026-102489 alone8.7 CVSS
- Chained9.4 CVSS
Source: DIVD CVE records for CVE-2026-102489 and CVE-2026-102490, accessed 2026-10-05
The second bug needs a foothold, so it is a local flaw with low privileges required. The first bug supplies the foothold without credentials. Neither score alone tells an operator that an internet-facing helpdesk goes from stranger to root in one session, which is the property attackers used.
Some outlets print 9.4 against each CVE individually. That is the chained figure, not a per-bug score.
What the intruder did, and the AI claim
DIVD says the intruder moved from a hijacked session to root in seconds. It attributes that speed to an agentic attack, and in its description the attacker "decided the next step itself, at the speed of light" with "sloppy logic", according to Secureblink. Sysdig's write-up reports password spraying and man-in-the-middle attempts after root, and data taken from the helpdesk: volunteer email addresses and ticket contents.
Treat the AI attribution as DIVD's inference from behaviour: verbose commentary inside intrusion scripts and non-deterministic steps. No sample or model is named in what we fetched. The practical point holds either way. Sysdig lists the detection signals as a service account spawning shells, privilege-escalation syscalls and unfamiliar outbound connections.
What to do now
CISA's alert cites binding operational directive BOD 26-04, which obliges federal civilian agencies to remediate. Security Affairs gives a deadline of October 5; the CISA text we fetched states no date, so check the catalog entry itself.
For everyone else: upgrade to Zammad 7, or pull the instance offline. Segment the helpdesk and set default-deny egress, as Sysdig recommends. Run DIVD's log script against logs from September 21 onward.
Two days after the Zammad entries, CISA listed the NetScaler SAML flaw too; our earlier piece on Cisco's SD-WAN authentication bypass covers another edge-device bug. Unlike those, the Zammad case comes with the victim's own timeline.
Sources
More in Security
- 01Pwn2Own Ireland 2026 Day One: Seven of 20 Listed Entries Were Collisions, and OpenAI Codex Fell to Argument InjectionSamsung's Galaxy S26 was hit three times, Sonos and Philips Hue each twice or more, and a Google Pixel 10 attempt ran out of time. Vendors get 90 days before details go public.
- 02Atlassian CVE-2026-21589: A 9.3 File-Access Flaw Hits Every Data Center Version of Eight ProductsAn unauthenticated request can read a file from the web root if the attacker already knows its exact path. Atlassian reports no exploitation and has released fixes for each product line.
- 03WordPress CVE-2026-87902: A Page-Template Bug in Every Release Since 4.7, Patched in 7.1.2The 9.2 rating describes a file include; code execution needs a theme folder starting with page- and a PHP setting, but probes began five hours after the patch.
- 04Citrix's September 27 NetScaler Fix Does Not Cover CVE-2026-88779, Now on CISA's Exploited ListBuilds that closed two exploited zero-days stay vulnerable to a SAML flaw that CISA added on October 4 with a three-day deadline.