CISA adds two Zammad vulnerabilities to KEV: CVE-2026-102489 (session fixation to RCE) and CVE-2026-102490 (local privilege escalation to root), chained in an agentic-AI attack on DIVD

CISA adds two Zammad vulnerabilities to KEV (TL-2026-2843), also tracked as DIVD-2026-00015, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-10-02. It has no confirmed attribution, affects Zammad GmbH Zammad (CVE-2026-102489, session fixation to RCE), references 2 CVEs (CVE-2026-102489, CVE-2026-102490), maps to 5 MITRE ATT&CK techniques (T1059, T1110.003, T1190), and is covered by 9 detection rules and 10 indicators of compromise.

Key facts for TL-2026-2843

Threat ID
TL-2026-2843
Also known as
DIVD-2026-00015, DIVD-2026-00014
Severity
CRITICAL
CVSS
9.8
Status
ACTIVE
Category
VULNERABILITY
First published
2026-10-02
Last reviewed
2026-10-02
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, government administration, non-profit organisation, customer-support
Target regions
Global, Europe
Detection rules
9
Indicators of compromise
10

Malware and tooling in CISA adds two Zammad vulnerabilities to KEV

Malware and tooling: Autonomous AI agent (undisclosed model/framework)

On 2026-10-02 CISA added CVE-2026-102489 (session fixation leading to RCE as the zammad user) and CVE-2026-102490 (zammad-to-root privilege escalation) in Zammad to the KEV catalog. The two flaws were chained as zero-days on 2026-09-21 to breach the Dutch Institute for Vulnerability Disclosure (DIVD), in what DIVD describes as an agentic AI-powered attack.

How CISA adds two Zammad vulnerabilities to KEV works

Zammad is an open-source web helpdesk and ticketing system. CVE-2026-102489 is a session fixation / session hijack flaw (CWE-384) in Zammad 6.3.0 through 6.5.4 that leads to remote code execution as the local zammad OS user. Versions 7.0.0 through 7.1.3 contain the defect but, per DIVD and the vendor, are not practically exploitable because of the runtime environment those releases use; the vendor states exploitation is only possible on Zammad 6.5 and older and that the issue is addressed in 7.2.0. CVE-2026-102490 (CWE-269, improper privilege management) lets the local zammad user escalate to root and is reported to affect Zammad 1.5.0 through 7.1.0-alpha on Linux and Docker. It cannot be exploited remotely on its own, but CISA's KEV entries state each can be chained with the other, turning an unauthenticated network attack into full operating-system compromise.

Both flaws were exploited as zero-days against DIVD's own Zammad instance. Initial malicious access occurred on 2026-09-21; DIVD detected the activity on 2026-09-22, blocked access, and engaged Merlon Security for forensics. DIVD reproduced the issues within about 24 hours during case DIVD-2026-00014 (the breach) and opened DIVD-2026-00015 (the Zammad vulnerabilities) for victim notification. DIVD reports the progression from session hijack to root took seconds and attributes the speed and behaviour to an autonomous AI agent: attack logs and scripts contained self-justifying comments, the agent decided each next step itself, and it polluted its own man-in-the-middle attempt with password spraying. Reported data exposure includes DIVD volunteer email addresses and possibly contact details; network segmentation reportedly contained the attacker and prevented persistent footholds. No attacker IPs, domains, hashes or user agents have been published.

There is a vendor/researcher dispute: Zammad states DIVD has not provided technical details for CVE-2026-102490, objects to the disclosure timeline, and as of its 2026-10-01 statement and the runZero write-up no official patch was announced for CVE-2026-102490, while one secondary source claims it is fixed from 7.1.0-alpha onward; treat the fix status of CVE-2026-102490 as unconfirmed. CVSS values vary by source: NVD lists 9.8 (v3.1) and 9.4 (v4.0) for both CVEs, while runZero cites 8.7 and 8.5 (CVSS v4) for the individual flaws and 9.4 for the chain. CISA marks Known Ransomware Campaign Use as Unknown, requires forensic triage, and set a due date of 2026-10-05 under BOD 26-04.

MITRE ATT&CK techniques used in TL-2026-2843

Execution

T1059 Command and Scripting Interpreter

Credential Access

T1110.003 Brute Force: Password Spraying; T1557 Adversary-in-the-Middle

Initial Access

T1190 Exploit Public-Facing Application

Collection

T1213 Data from Information Repositories

Affected products and versions in CISA adds two Zammad vulnerabilities to KEV

  • Zammad GmbH — Zammad (CVE-2026-102489, session fixation to RCE)
    Vulnerable versions: 6.3.0 through 6.5.4 (exploitable); 7.0.0 through 7.1.3 (defect present, not practically exploitable)
    Fixed in: 7.2.0
  • Zammad GmbH — Zammad on Linux and Docker (CVE-2026-102490, zammad-to-root privilege escalation)
    Vulnerable versions: 1.5.0 through 7.1.0-alpha

Remediation for CISA adds two Zammad vulnerabilities to KEV

Patches

  • CVE-2026-102489: addressed in Zammad 7.2.0 (7.0+ not practically exploitable)
  • CVE-2026-102490: no official patch confirmed as of 2026-10-01; fix status disputed between DIVD and vendor

Immediate actions

  • Upgrade Zammad to 7.2.0 or later (current stable); versions 6.5 and earlier are end-of-support and receive no security fixes
  • If an upgrade is not possible, take the Zammad instance offline or remove internet exposure (CISA: discontinue use if mitigations are unavailable)
  • Run DIVD's log check script (cve-2026-102489_ioc_check_script_v2.sh) against Zammad logs to look for indicators of compromise
  • Preserve application, web server, authentication and system logs and perform forensic triage as CISA requires; treat any exposed 6.3.0-6.5.4 instance as potentially compromised to root
  • Rotate credentials and secrets reachable from the Zammad host

Workarounds

  • Take the instance offline until upgraded
  • Review logs for suspicious sessions, unexpected administrative activity and command execution as the zammad user, and for the zammad user spawning root processes

Longer-term hardening

  • Segment helpdesk infrastructure from other services so a Zammad compromise cannot reach adjacent systems (segmentation contained the DIVD intrusion)
  • Inventory Zammad deployments (dpkg -l zammad, rpm -q zammad, docker image listing) and restrict the UI from the internet unless required
  • Monitor the Zammad GitHub security advisories for the CVE-2026-102490 fix status

CVEs associated with CISA adds two Zammad vulnerabilities to KEV

CVE-2026-102489, CVE-2026-102490

Weaknesses (CWE) in CISA adds two Zammad vulnerabilities to KEV

CWE-384, CWE-269

Timeline of CISA adds two Zammad vulnerabilities to KEV

  • Attacker gains initial access to DIVD's Zammad instance by chaining CVE-2026-102489 and CVE-2026-102490 as zero-days; the progression from session hijack to root takes seconds.
  • DIVD detects the malicious activity, blocks access, and engages Merlon Security for incident response and forensics.
  • DIVD analyses and reproduces both vulnerabilities (analysis spanned 2026-09-22 to 2026-09-23).
  • DIVD reports the vulnerabilities to Zammad.
  • Case DIVD-2026-00015 opened and CVE IDs assigned; DIVD begins internet scanning and notifying owners of exposed Zammad instances.
  • DIVD publicly identifies the two Zammad zero-days as the attack vector for its breach and describes the attack as agentic AI-powered.
  • Zammad publishes its security statement: CVE-2026-102489 addressed in 7.2.0, no technical details received for CVE-2026-102490, and it objects to the disclosure timeline; DIVD publishes its data-breach overview.
  • CISA adds CVE-2026-102489 and CVE-2026-102490 to the KEV Catalog citing evidence of active exploitation.
  • CISA KEV remediation due date for both CVEs under BOD 26-04.

Sources cited for CISA adds two Zammad vulnerabilities to KEV

More in vulnerability

Detection coverage for TL-2026-2843

As of 2026-10-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2843 across Splunk SPL, Microsoft KQL and Sigma, covering 10 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats