Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-04 · updated: 2026-10-04 · tags: [incident, global, zero-day] · confidence: high · severity: critical · affected_sectors: [global] · au_impact: true

CISA added CVE-2026-102489 and CVE-2026-102490 in the Zammad open-source helpdesk and support-ticketing platform to its Known Exploited Vulnerabilities (KEV) catalogue on 2 October, based on evidence of active exploitation. The pair comprises a session-fixation vulnerability that can lead to remote code execution (CVE-2026-102489) and an improper privilege-management flaw (CVE-2026-102490). Zammad is widely deployed by public- and private-sector organisations as customer-support and service-desk infrastructure, and the session-fixation-to-RCE chain makes these the day's most operationally urgent disclosures — an exploited edge of the same "fix before it is weaponised" class as the FortiMail zero-day earlier in the week. CISA requirements under Binding Operational Directive 22-01 give US federal agencies a deadline to remediate; Australian and New Zealand operators of self-hosted Zammad instances should treat the entries as a patch priority.

Attribute Detail
Sector Global (Macro)
Date 2026-10-04
Source CISA
Reliability Tier 1
CVEs CVE-2026-102489, CVE-2026-102490