Two Zammad bugs are on the CISA Known Exploited Vulnerabilities list, and they have already been chained to root.
What happened
On 2 October, CISA added CVE-2026-102489 and CVE-2026-102490. The first is a session-fixation issue that can reach remote code execution as the zammad user. The second lets that local user escalate to root. The federal due date is 5 October.
The Dutch Institute for Vulnerability Disclosure says both were used as zero-days in an agentic AI attack against its own infrastructure on 21 September. DIVD says the chain hijacked sessions, ran code, and escalated to root in seconds, then pivoted and exfiltrated data until segmentation stopped a deeper move.
Who is affected
- Internet-facing Zammad helpdesks that are not on Zammad 7
- Anyone hosting it for a client, not only the teams that run it internally
What to do now
- Move to Zammad 7, or take the instance offline. DIVD also published a verification script for indicators.
- Treat this as an incident-response check, not a backlog item. Helpdesk software is often internet-facing and full of customer tickets.
Source: CISA KEV alert, 2 October 2026
Also on the blog
- GitLab AI Gateway sandbox escape is a 9.9, patches are out
- FortiMail zero-day is exploited, and most fixes are not shipped
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.