CISA Adds Two Zammad Vulnerabilities to Known Exploited Vulnerabilities Catalog
CISA has added two vulnerabilities affecting Zammad GmbH's Zammad software to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially added two new vulnerabilities to its catalog of Known Exploited Vulnerabilities (KEV), signaling that these flaws are actively being targeted by malicious actors. The vulnerabilities, identified as CVE-2026-102489 and CVE-2026-102490, both impact the Zammad software developed by Zammad GmbH.
CVE-2026-102489 is described as a session fixation vulnerability. This type of flaw allows an attacker to hijack a user's session by manipulating the session identifier, potentially gaining unauthorized access to the user's account and data. Session fixation attacks are particularly dangerous as they can be used to bypass authentication mechanisms if not properly handled by the application.
Complementing this, CVE-2026-102490 addresses an improper privilege management issue within the Zammad software. Vulnerabilities in privilege management can allow authenticated users, or even unauthenticated attackers in some cases, to escalate their privileges beyond what they are intended to have. This could grant them administrative access or the ability to perform actions normally reserved for privileged users, leading to significant system compromise.
CISA's inclusion of these vulnerabilities in the KEV Catalog is based on concrete evidence of their active exploitation in the wild. This means that threat actors are already leveraging these weaknesses to compromise systems, posing an immediate risk to organizations that have not yet applied patches or implemented mitigations.
Federal Civilian Executive Branch (FCEB) agencies are mandated by Binding Operational Directive (BOD) 26-04 to prioritize the remediation of vulnerabilities listed in the KEV Catalog, especially on publicly exposed assets. This directive emphasizes a risk-based approach, requiring agencies to focus on vulnerabilities that grant total control of an asset post-exploitation. While BOD 26-04 specifically targets federal agencies, CISA strongly encourages all organizations, regardless of sector, to adopt similar risk-based vulnerability management practices.
The inclusion in the KEV Catalog serves as a critical alert, prompting organizations to review their Zammad deployments and ensure that systems are updated to the latest secure versions. Failure to do so could expose them to data breaches, service disruptions, and other cyber threats.
CISA continues to monitor the threat landscape and will add new vulnerabilities to the KEV Catalog as evidence of exploitation emerges. The agency also provides a nomination form for the public to submit vulnerabilities that they believe meet the criteria for inclusion, requiring a CVE ID, proof of exploitation, and clear mitigation guidance.
Organizations using Zammad software should consult Zammad GmbH's official security advisories for specific patch details and recommended actions to protect their environments from these actively exploited vulnerabilities.