If you run Zammad — the open-source helpdesk and ticketing platform — as your customer support inbox, stop reading and check your version. CISA just added two actively exploited flaws to its Known Exploited Vulnerabilities (KEV) catalog, and together they take an internet-facing install from zero to full root compromise on the underlying server. This is not a theoretical chain. It was used to breach the Dutch Institute for Vulnerability Disclosure (DIVD) in a real-world attack.
What’s Going On
Zammad is one of the most popular self-hosted helpdesk apps — teams run it for email, ticket handling, and support chat. On October 2, CISA added two vulnerabilities to the KEV catalog, meaning attackers are confirmed to be using them right now. Both were originally discovered in September and chained together as zero-days against DIVD’s own infrastructure.
The Two Flaws, Explained
CVE-2026-102489 (session fixation, CVSS 9.8): This affects the web front end of Zammad 6.3.0 through 6.5.4. Session fixation means an attacker can force or trick a user into using a session identifier the attacker already controls. The end result is remote code execution (RCE) as the local zammad service user — no credentials, no phishing, no prior access to your network. The same defect technically exists in 7.0.0 through 7.1.3, but the vendor says the runtime environment in those releases makes it not practically exploitable.
CVE-2026-102490 (local privilege escalation, CVSS 9.8): This lets the local zammad user escalate straight to root. It reportedly affects Zammad 1.5.0 through 7.1.0-alpha — effectively every shipped version. It cannot be exploited remotely on its own, which is exactly why the two flaws are dangerous as a pair: the session-fixation bug gets the attacker a foothold as the low-privileged zammad user, and the privilege escalation bug does the rest. One unauthenticated internet request becomes a full operating-system takeover.
CISA rates both at CVSS 9.8 and set a BOD 26-04 remediation deadline of October 5 for federal civilian agencies.
Why You Should Treat This as Urgent
The technical detail that should make you move: these two vulnerabilities were chained in a live attack against DIVD — an organization whose entire job is discovering and disclosing security flaws. They got hit despite being security professionals. If that ticketing instance of yours is reachable from the internet, treat it as potentially compromised right now. Unauthenticated RCE that escalates to root is the exact kind of chain ransomware operators and state actors live for.
What to Do Immediately
- Upgrade to Zammad 7.2.0 now. This is the version that includes the security hardening for CVE-2026-102489. It shipped September 23, 2026 — before the attacks were made public. If you are on anything below 7.2.0, that fix is what you are missing.
- If you cannot upgrade immediately, take the instance offline. An exposed Zammad running an affected version is worse than a temporarily unavailable helpdesk. CISA’s own guidance says discontinue use if mitigations aren’t available.
- Versions 6.5 and earlier are end-of-support. They receive no security fixes at all. There is no scenario where staying on 6.x is acceptable at this point.
- Hunt for prior compromise before you celebrate the patch. Run DIVD’s IOC check script (cve-2026-102489_ioc_check_script_v2.sh) against your Zammad logs, and preserve your application, web server, authentication, and system logs for forensic review.
- Treat any internet-exposed 6.x instance as fully owned. Rotate every credential and secret reachable from that host, including database passwords, API keys, and anything stored in the helpdesk’s mail or chat integrations.
The Bottom Line
There is some back-and-forth between Zammad and DIVD about the exact scope of CVE-2026-102490’s privilege escalation — the vendor initially said it hadn’t received the technical details. CISA is not interested in that dispute. Both bugs are on the KEV list, active exploitation is confirmed, and the chain ends in root. Upgrade to 7.2.0, pull exposed instances off the internet if you can’t, and check your logs for signs someone already got there first. Waiting on a self-hosted helpdesk is a luxury you do not have this week.