NCSC-NL and DIVD say two Zammad zero-days were chained in an active breach, with exploitation underway since 21 September 2026. One flaw, CVE-2026-102489, lets an unauthenticated remote attacker run code in Zammad 6.3.0 through 6.5.4; the second, CVE-2026-102490, turns low privileges into root on the host.
That combination matters because the first bug gets code running and the second raises it to full system control. DIVD says the chain let attackers hijack sessions, execute code, and reach root quickly, then read and exfiltrate data from connected services.
The lasting exposure is on any self-hosted Zammad instance that stays on the vulnerable major line: fixing only the disclosed RCE still leaves a route from help desk access to host takeover. For teams that use ticketing systems as a bridge into internal services, the trust boundary sits in the help desk layer itself.
The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system.
Rilasciati aggiornamenti di sicurezza per risolvere 30 vulnerabilità, di cui 1 con gravità "critica" e 10 con gravità “alta”, presenti nel prodotto Zammad, soluzione open source per la gestione dell’help desk e del supporto clienti.