A session fixation vulnerability in Zammad GmbH's Zammad helpdesk software, identified as CVE-2026-102489, was exploited on the same day it was publicly disclosed. The vulnerability, which carries a high severity rating, can lead to remote code execution as the `zammad` user and can be chained with another local privilege escalation flaw, CVE-2026-102490.
The CVE for the session fixation vulnerability was reserved on September 29, 2026, and published on September 30, 2026. On that same day, September 30, it was added to the European Union's ENISA KEV (EUVD) and VulnCheck's commercial KEV catalog, indicating immediate exploitation in the wild. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) subsequently added both CVE-2026-102489 and CVE-2026-102490 to its Known Exploited Vulnerabilities (KEV) catalog on October 2, 2026.
CISA has mandated that federal agencies address these vulnerabilities by October 5, 2026, in accordance with its BOD 26-04 guidance on prioritizing security updates. Agencies are instructed to apply vendor-provided mitigations or discontinue use of the product if mitigations are unavailable, while also evaluating internet exposure of their assets.
Public exploitation evidence, reported on September 30, 2026, includes a case from the Dutch Institute for Vulnerability Disclosure (DIVD). The DIVD, a cybersecurity non-profit, disclosed that it was compromised in an attack that leveraged two zero-day vulnerabilities in its Zammad helpdesk platform. The incident, detected on September 24, reportedly involved the use of an "agentic AI" to execute the attack.
The Zammad GmbH website and community forum contain references to releases and discussions regarding the local privilege escalation vulnerability, CVE-2026-102490, which can be chained with the session fixation flaw. The rapid exploitation of CVE-2026-102489 highlights the critical need for immediate patching upon disclosure of such vulnerabilities.






