CISA Warns of Zammad DIVD Vulnerabilities Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


The U.S. Cybersecurity and Infrastructure Security Agency has added two Zammad vulnerabilities to its Known Exploited Vulnerabilities catalog after reports that attackers are actively exploiting at least one flaw.

The issues, tracked as CVE-2026-102489 and CVE-2026-102490, can be chained to gain high-level control of affected Zammad helpdesk servers.

Zammad is an open-source customer support and ticketing platform that organizations use to manage service requests, customer communications, and internal support operations.

Because these systems can contain sensitive customer data, support tickets, credentials, and email integrations, a compromise could create a significant security risk.

CVE-2026-102489 is a session fixation vulnerability affecting older Zammad installations. Session fixation occurs when an attacker forces or tricks a target into using a session identifier the attacker already knows.

According to the vulnerability record, successful exploitation could allow remote code execution as the low-privileged Zammad user.

The second issue, CVE-2026-102490, is an improper privilege management vulnerability. It could allow a local Zammad user to elevate privileges to root, the highest-privileged account on Linux systems. When chained with the session fixation flaw, attackers could potentially move from remote access to full server takeover.

CISA added both vulnerabilities to its catalog on October 2, 2026, and set an October 5, 2026 remediation deadline for federal civilian agencies.

The agency said forensic triage is required under Binding Operational Directive 26-04, indicating that organizations should investigate affected systems for signs of compromise in addition to applying mitigations.

Zammad acknowledged public reports tied to DIVD case DIVD-2026-00015. However, the company said CVE-2026-102489 is exploitable only on Zammad 6.5 and earlier, which are no longer supported.

Zammad said versions 7.0 and later are not affected in practice, and that Zammad 7.2.0 included additional code hardening. The vendor initially said it had not received technical information for CVE-2026-102490 and could not verify the reported scope or exploitation claims.

In a later update, Zammad said it received the vulnerability details from DIVD and confirmed that the privilege-escalation issue cannot be exploited remotely on its own.

An attacker would first need server access. Administrators should update to Zammad 7.2.0, especially if they operate version 6.5 or older.

Organizations should also review server logs, running processes, user accounts, scheduled tasks, SSH access, web server logs, and unusual outbound connections for evidence of unauthorized access.

CISA recommends applying vendor mitigations, assessing internet exposure, and discontinuing use of the product if adequate mitigations are unavailable.

The case highlights the danger of combining separate weaknesses: one flaw may provide initial access, while another can turn limited access into complete administrative control.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post CISA Warns of Zammad DIVD Vulnerabilities Actively Exploited in Attacks appeared first on Cyber Security News.