LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
CVE-2026-102489

U.S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in Zammad GmbH's Zammad helpdesk software to its Known Exploited Vulnerabilities (KEV) catalog, mandating that federal agencies address them by October 5, 2026. These flaws, identified as CVE-2026-102489 and CVE-2026-102490, have been actively exploited in the wild, including in a recent breach of…

ZeroDay News ·

Source: Security Affairs

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in Zammad GmbH's Zammad helpdesk software to its Known Exploited Vulnerabilities (KEV) catalog, mandating that federal agencies address them by October 5, 2026. These flaws, identified as CVE-2026-102489 and CVE-2026-102490, have been actively exploited in the wild, including in a recent breach of the Dutch Institute for Vulnerability Disclosure (DIVD).

CVE-2026-102489, with a CVSS score of 9.4, is a session fixation vulnerability that can lead to remote code execution as the `zammad` user. This flaw affects Zammad versions 6.3.0 through 6.5.4, and also versions 7.0.0 through 7.1.3. The second vulnerability, CVE-2026-102490, also rated with a CVSS score of 9.4, is an improper privilege management vulnerability. It allows the `zammad` user to escalate privileges to root and impacts Zammad versions from 1.5.0 through 7.1.0-alpha.

The DIVD, a nonprofit organization of volunteer security researchers, confirmed it was breached through the exploitation of these two zero-day vulnerabilities in its internal Zammad ticketing system. The attackers chained CVE-2026-102489 to gain initial code execution as the `zammad` user, then used CVE-2026-102490 to escalate to root privileges. DIVD, working with Merlon Security, identified these previously unknown flaws during its incident response.

The speed of the attack was notable, with the attackers moving from initial access to root privileges within seconds. DIVD attributed this rapid progression to the use of an AI agent, which was capable of making decisions and executing subsequent steps without direct human intervention. This agent was able to analyze the environment, chain the vulnerabilities, and escalate privileges to access other services, read, and exfiltrate data.

Following the root access gained through Zammad, the attackers accessed other services and stole some data. However, network segmentation and a swift response from DIVD’s IT and incident response teams prevented further lateral movement. DIVD stated that some damage had occurred before the attack was halted, and the investigation remains ongoing.

Zammad, which serves over 2,000 customers and 55,000 users, has advised all users to update to version 7 or take their systems offline immediately if an update is not possible. Version 7 is considered safe by Zammad. DIVD is actively notifying owners of vulnerable instances and has provided a script to help organizations check their logs for signs of abuse.

The incident highlights the growing threat of AI-driven attacks, demonstrating that such capabilities are no longer merely theoretical. While the AI agent in this attack left visible traces, aiding investigators, a more sophisticated or discreet agent could pose a greater detection challenge. CISA's inclusion of these vulnerabilities in its KEV catalog underscores the critical need for all organizations, including private entities, to review and address these flaws in their infrastructure to protect against similar exploits.

vulnerabilities in this storyCVE-2026-102489
vulnerabilitycloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-88779

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Citrix has confirmed the active exploitation of a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler appliances. This new flaw reportedly emerged and was exploited just days after the company released patches for two other previously exploited vulnerabilities in the same product line.

CVE-2026-88779high

Citrix NetScaler Flaw Exploited Before CVE Publication

The CVE-2026-88779 vulnerability in Citrix NetScaler was exploited before its official publication date. A second independent catalogue now confirms exploitation.

CVE-2026-88779

Citrix patches NetScaler SAML zero-day exploited in attacks

Citrix has issued urgent security updates for a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler ADC and NetScaler Gateway appliances. The flaw, described as a memory buffer issue, has been actively exploited in targeted attacks, primarily leading to denial-of-service conditions.

patch

Three questions a hospital CISO should ask a healthcare fintech vendor

A cybersecurity expert has outlined key questions hospital CISOs should pose to healthcare fintech vendors to assess their security posture, particularly concerning patient data and financial transactions. Drew McCombs, who holds both CTO and CISO roles at Cylerity, emphasizes that security should be an integral part of development processes, not an afterthought, especially when patient data…

cloud

Keyorix: Open-source secrets management for teams that can’t use SaaS

Keyorix, an open-source secrets management solution, has been released, offering an on-premises alternative for organizations unable to utilize cloud-based services for credential storage. The system is designed to run entirely on a company's own infrastructure, with its core functionality requiring no internet connection.

security

How RMM abuse gives attackers a way in that looks like business as usual

Attackers are increasingly leveraging legitimate remote monitoring and management (RMM) software to gain persistent access to victim systems, a tactic observed in 45% of endpoint-related incidents recorded by security firm Huntress in the first quarter of 2026. This method allows attackers to execute commands remotely and maintain access in a way that often appears to be normal administrative…