CISA adds exploited Zammad zero-days used in DIVD breach to KEV catalog
CISA has added two actively exploited Zammad flaws to its KEV catalog. The chain was used to breach Dutch nonprofit DIVD, and the root escalation bug reportedly remains unpatched.
At a glance
- CISA added CVE-2026-102489 and CVE-2026-102490 in the Zammad helpdesk platform to its KEV catalog on October 2
- The two flaws were chained in a September 21 breach of the Dutch Institute for Vulnerability Disclosure (DIVD)
- Upgrading to Zammad 7 blocks the remote entry point, but the privilege escalation flaw reportedly has no patch yet
- DIVD has published a log-check script to help administrators look for signs of compromise
The US Cybersecurity and Infrastructure Security Agency (CISA) on October 2 added two vulnerabilities in Zammad, a widely used open-source helpdesk and ticketing platform, to its Known Exploited Vulnerabilities (KEV) catalog. The flaws, tracked as CVE-2026-102489 and CVE-2026-102490, were chained together in a September 21 intrusion at the Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit that itself specializes in warning organizations about vulnerable systems. The KEV listing confirms active exploitation and puts pressure on organizations running Zammad to act quickly.
What happened
According to SecurityWeek, DIVD disclosed on September 24 that attackers had compromised its Zammad instance and described the incident as "an agentic AI-powered attack." SecurityOnline reports that DIVD based this assessment on the attacker's scripts, which contained unusual self-justifying comments. According to the reports, the chain took the attacker from unauthenticated access to root on the server within seconds.
SecurityWeek reports that the attacker then pivoted to additional services and exfiltrated data, but network segmentation limited the damage. DIVD said it is assuming compromise while its investigation continues. CISA's catalog lists CVE-2026-102489 as a session fixation issue and CVE-2026-102490 as an improper privilege management flaw.
Technical details
According to SecurityWeek and Tech Times, CVE-2026-102489 allows an unauthenticated attacker to leak user sessions and execute code on the server as the Zammad service account. It is exploitable in Zammad 6.3.0 through 6.5.4. Tech Times reports that the bug is also present in 7.0.0 to 7.1.3, but is not currently exploitable there due to environmental conditions.
CVE-2026-102490 is a local privilege escalation flaw that lets an attacker who already runs code as the Zammad service user become root. According to SecurityOnline and Tech Times, it affects nearly all releases, from 1.5.0 through 7.1.0-alpha, and Tech Times reported that no patch was available as of October 1. SecurityWeek reported a CVSS score of 9.4 for both flaws, while SecurityOnline cited different individual scores, so exact ratings should be confirmed against the official advisories.
Who is affected
Zammad is used by more than 2,000 organizations, according to the reports. Any internet-facing instance on the 6.x branch is at direct risk of remote compromise, and all installations remain exposed to the root escalation if an attacker gains code execution by another route.
What to do
DIVD recommends upgrading to Zammad version 7 immediately or taking vulnerable instances offline. Additional steps recommended in the reports include:
- Restricting access to Zammad behind a VPN or removing direct internet exposure where possible
- Running DIVD's published log-check script to look for indicators of compromise
- Reviewing audit logs for unusual administrative activity
- Rotating credentials and secrets stored on any server suspected of compromise
US federal civilian agencies are required to remediate KEV-listed flaws within the deadline set by CISA, and the agency urges all organizations to prioritize them.
Related CVEs
Sources
- Known Exploited Vulnerabilities Catalog — CISA
- Zammad Zero-Days Exploited in AI-Powered DIVD Hack — SecurityWeek
- Zammad Zero-Day Chain CVE-2026-102489 Exploited in the Wild in AI-Driven DIVD Breach — SecurityOnline
- AI Agent Hacked Cybersecurity Nonprofit DIVD via Zammad Zero-Days; Root Flaw Unpatched — Tech Times
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



