Vulnerabilities · 5h ago
NCSC-NL and DIVD say two Zammad zero-days were chained in an active breach, with exploitation underway since 21 September 2026. One flaw, CVE-2026-102489, lets an unauthenticated remote attacker run code in Zammad 6.3.0 through 6.5.4; the second, CVE-2026-102490, turns low privileges into root on the host.
That combination matters because the first bug gets code running and the second raises it to full system control. DIVD says the chain let attackers hijack sessions, execute code, and reach root quickly, then read and exfiltrate data from connected services.
The lasting exposure is on any self-hosted Zammad instance that stays on the vulnerable major line: fixing only the disclosed RCE still leaves a route from help desk access to host takeover. For teams that use ticketing systems as a bridge into internal services, the trust boundary sits in the help desk layer itself.
3 sources covering this story
Kwetsbaarheden aangetroffen in Zammad
De eerste kwetsbaarheid heeft het kenmerk CVE-2026-102489 toegekend gekregen.
DIVD says Zammad zero-days enabled AI-driven network breach
The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system.
Risolte vulnerabilità in Zammad
Rilasciati aggiornamenti di sicurezza per risolvere 30 vulnerabilità, di cui 1 con gravità "critica" e 10 con gravità “alta”, presenti nel prodotto Zammad, soluzione open source per la gestione dell’help desk e del supporto clienti.
Part of the PlainSec briefing for 2026-09-30