CISA added CVE-2026-102489 and CVE-2026-102490 in the Zammad open-source helpdesk and support-ticketing platform to its Known Exploited Vulnerabilities (KEV) catalogue on 2 October, based on evidence of active exploitation. The pair comprises a session-fixation vulnerability that can lead to remote code execution (CVE-2026-102489) and an improper privilege-management flaw (CVE-2026-102490). Zammad is widely deployed by public- and private-sector organisations as customer-support and service-desk infrastructure, and the session-fixation-to-RCE chain makes these the day's most operationally urgent disclosures — an exploited edge of the same "fix before it is weaponised" class as the FortiMail zero-day earlier in the week. CISA requirements under Binding Operational Directive 22-01 give US federal agencies a deadline to remediate; Australian and New Zealand operators of self-hosted Zammad instances should treat the entries as a patch priority.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-10-04 |
| Source | CISA |
| Reliability | Tier 1 |
| CVEs | CVE-2026-102489, CVE-2026-102490 |