A critical improper privilege management vulnerability, identified as CVE-2026-102490, in the Zammad GmbH Zammad helpdesk platform was exploited on the same day it was publicly disclosed. The vulnerability allows a local Zammad user to escalate privileges to root access.
The CVE was reserved on September 29, 2026, and officially published on September 30, 2026. Within hours of its publication, evidence of in-the-wild exploitation emerged, leading to its inclusion in multiple Known Exploited Vulnerabilities (KEV) catalogs. The European Union Agency for Cybersecurity (ENISA) and VulnCheck KEV both listed the vulnerability as exploited on September 30, 2026, while the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added it to its KEV catalog on October 2, 2026.
This vulnerability can be chained with another critical flaw, CVE-2026-102489, which was also exploited in attacks. The Dutch Institute for Vulnerability Disclosure (DIVD), a cybersecurity non-profit, confirmed it was compromised in an attack leveraging these two zero-day vulnerabilities in its Zammad helpdesk platform. The incident at DIVD was detected on September 24, and the organization indicated that an "agentic AI" was used to execute the attack.
CISA has issued a directive for federal agencies to apply mitigations in accordance with vendor instructions by October 5, 2026. This includes adhering to CISA’s BOD 26-04 guidance on prioritizing security updates and forensics triage requirements. For cloud services, applicable BOD 26-04 guidance must be followed, or the product discontinued if mitigations are unavailable.
The vulnerability has a high severity rating with an EPSS score of 0.63%, placing it in the 48.3rd percentile for exploitability. Public reports of exploitation were collected from VulnCheck and CIRCL, with the earliest sighting on September 30, 2026. Zammad GmbH has released updates to address these vulnerabilities, and users are urged to apply them immediately.






