Zammad Disputes DIVD Over Two Zero-Days Now on CISA's Exploited List
Security / news
Zammad Disputes DIVD Over Two Zero-Days Now on CISA's Exploited List
The Dutch vulnerability-disclosure group says it was breached on Sept. 21 through CVE-2026-102489 and CVE-2026-102490, while Zammad says the second flaw needs prior server access and the version ranges still disagree.
Federal agencies had until Oct. 5 to deal with two Zammad flaws, CVE-2026-102489 and CVE-2026-102490, after CISA added both to its Known Exploited Vulnerabilities catalog on Oct. 2. The first is a session-fixation bug that gives code execution as the zammad service user, and the second lets that user become root. The fix path is unsettled: Zammad has shipped hardening for the first flaw in version 7.2.0, and no source has confirmed a vendor patch for the second.
The flaws came to light because they were used against the group that exists to report such flaws. The Dutch Institute for Vulnerability Disclosure (DIVD), a volunteer nonprofit, says an attacker first reached its systems on Sept. 21 by abusing its own Zammad helpdesk install. DIVD is also the CVE numbering authority that assigned both IDs, which is one reason the disclosure is contested.
What each flaw needs and what it gives
CVE-2026-102489 is a session hijack that leads to remote code execution as the zammad user, according to DIVD's case file DIVD-2026-00015. CVE-2026-102490 is a local privilege escalation from that user to root. The second needs code already running on the host, so on its own it is a second-stage tool, not an entry point. Chained, the pair takes an attacker from a web request to root.
The score overstates the standalone risk of the second flaw. The NVD record gives both CVEs 9.8 on CVSS 3.1, according to the runZero write-up by software engineer Matthew Kienow, even though the second is described as local. DIVD's own CVSS 4.0 scores are 8.7 and 8.5 for the two flaws alone, and 9.4 for the chain.
| Source | CVE-2026-102489 | CVE-2026-102490 |
|---|---|---|
| DIVD case file | 6.3.0 to 6.5.4 exploitable; 7.0.0 to 7.1.3 present, not exploitable | 1.5.0 to 7.1.0-alpha |
| Zammad forum post | 6.5 and older affected; 7.0 and later not | No list; not remotely exploitable alone |
Zammad 6.5 and older no longer receive security fixes, so a 6.5.4 install is exposed on either vendor's account.
The breach timeline
- Sept. 21: first malicious access, per DIVD.
- Sept. 22: DIVD detects the activity and blocks access to its datacenter systems.
- Sept. 24: DIVD reports the flaws to Zammad and posts its first public statement.
- Sept. 26: DIVD starts notifying owners of exposed instances and publishes a limited disclosure.
- Sept. 30: NVD publishes both CVEs.
- Oct. 2: CISA adds both to the KEV catalog.
DIVD says the attacker pivoted from Zammad to other services and exfiltrated data, and that network segmentation stopped it going deeper. The volunteer data exposed includes DIVD email addresses and possibly contact details. DIVD told readers that if a message from someone at DIVD feels off, they should check with [email protected] first.
Where Zammad disagrees
Zammad posted on its community forum at 12:16 UTC on Oct. 1. It said it had received a report on CVE-2026-102489 in August 2026, that DIVD had given it no technical details on the second flaw, and that "We cannot verify a claim we have not been shown." It called reporting on Sept. 24 and publishing on Sept. 26 "not a responsible way to handle vulnerabilities."
A later post at 19:48 UTC said that after receiving details, Zammad judged the escalation flaw "cannot be exploited remotely on its own" and needs prior server access, according to runZero's account of it. Zammad does not dispute that the chain worked against DIVD. It does not address DIVD's breach account at all.
The AI claim rests on DIVD alone. DIVD says the intrusion was driven by an AI agent that left notes justifying its own actions in attacker scripts, and that it went from session hijack to root in seconds. BleepingComputer reported no independent analysis of the claim, and DIVD has published only two redacted log screenshots as evidence. DIVD found no link to a known threat actor.
What to do on a Zammad install
Update to 7.2.0, which Zammad says includes hardening for the first flaw, or take the instance offline, as DIVD advises. Moving to version 7 may not close the second flaw. DIVD's script, cve-2026-102489_ioc_check_script_v2.sh, searches Zammad and nginx logs for session indicators; read it before running it. No hashes, IP addresses or domains have been published by DIVD, CISA or Zammad.
DIVD says the entry point was not Citrix NetScaler, the appliance covered in our report on the NetScaler zero-days, which was in the news the same week. A different vendor's mail product drew its own exploited-flaw listing on Oct. 1, covered in the FortiMail path-traversal report.
The number to watch is Zammad's GitHub security advisories page. As of runZero's Oct. 2 update it held no entry for either CVE.
Sources
More in Security
- 01CISA Gave Agencies Three Days for Five 2015-2023 Bugs, and Four Come With a Forensic Triage OrderThe October 8 additions to the exploited-vulnerabilities catalogue show how BOD 26-04 has changed what a deadline means: the patch is the smaller job.
- 02Apple's CoreGraphics Zero-Day CVE-2026-86950 Has a CISA Deadline of October 13, Not the October 2 Being ReportedTrade coverage gives a three-day federal deadline. The catalogue entry itself carries 14 days and no forensic-triage flag.
- 03Rejetto HFS CVE-2026-61500, Found With Anthropic's Mythos, Was Probed One Day After DisclosureA predictable session-signing key lets an unauthenticated attacker forge an HFS admin cookie and run server-side JavaScript; HFS 3.2.1 has carried the fix since July.
- 04Exchange CVE-2026-96940 Lets Any Mailbox User Read Others' Mail, and Patched Servers Need V2Microsoft's out-of-band September V2 update closes an 8.8-rated authorization flaw in on-premises Exchange, with four KBs and a support cliff for 2016 and 2019.