CISA adds exploited Zammad zero-days used in DIVD breach to KEV catalog
CISA has added two actively exploited Zammad flaws to its KEV catalog. The chain was used to breach Dutch nonprofit DIVD, and the root escalation bug reportedly remains unpatched.
