LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
CVE-2026-102489high

Zammad Session Fixation Vulnerability Exploited Same Day as Disclosure

CVE-2026-102489, a session fixation vulnerability in Zammad GmbH Zammad, was exploited on the same day it was published. The vulnerability is now listed in multiple exploitation catalogues.

ZeroDay News ·

A session fixation vulnerability in Zammad GmbH's Zammad helpdesk software, identified as CVE-2026-102489, was exploited on the same day it was publicly disclosed. The vulnerability, which carries a high severity rating, can lead to remote code execution as the `zammad` user and can be chained with another local privilege escalation flaw, CVE-2026-102490.

The CVE for the session fixation vulnerability was reserved on September 29, 2026, and published on September 30, 2026. On that same day, September 30, it was added to the European Union's ENISA KEV (EUVD) and VulnCheck's commercial KEV catalog, indicating immediate exploitation in the wild. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) subsequently added both CVE-2026-102489 and CVE-2026-102490 to its Known Exploited Vulnerabilities (KEV) catalog on October 2, 2026.

CISA has mandated that federal agencies address these vulnerabilities by October 5, 2026, in accordance with its BOD 26-04 guidance on prioritizing security updates. Agencies are instructed to apply vendor-provided mitigations or discontinue use of the product if mitigations are unavailable, while also evaluating internet exposure of their assets.

Public exploitation evidence, reported on September 30, 2026, includes a case from the Dutch Institute for Vulnerability Disclosure (DIVD). The DIVD, a cybersecurity non-profit, disclosed that it was compromised in an attack that leveraged two zero-day vulnerabilities in its Zammad helpdesk platform. The incident, detected on September 24, reportedly involved the use of an "agentic AI" to execute the attack.

The Zammad GmbH website and community forum contain references to releases and discussions regarding the local privilege escalation vulnerability, CVE-2026-102490, which can be chained with the session fixation flaw. The rapid exploitation of CVE-2026-102489 highlights the critical need for immediate patching upon disclosure of such vulnerabilities.

vulnerabilities in this storyCVE-2026-102489
vulnerability
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-88779high

Citrix NetScaler Flaw Exploited Before CVE Publication

The CVE-2026-88779 vulnerability in Citrix NetScaler was exploited before its official publication date. A second independent catalogue now confirms exploitation.

CVE-2026-88779

Citrix patches NetScaler SAML zero-day exploited in attacks

Citrix has issued urgent security updates for a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler ADC and NetScaler Gateway appliances. The flaw, described as a memory buffer issue, has been actively exploited in targeted attacks, primarily leading to denial-of-service conditions.

CVE-2026-88779high

NetScaler CVE-2026-88779 Exploited Before Publication

NetScaler's CVE-2026-88779 was exploited before its official publication date, leaving no patch window. The European Union's EUVD catalogue lists it as exploited.

nation-state

TTY Logs and the Data it Captures, (Sun, Oct 4th)

A recent report details an experiment involving the collection and analysis of TTY logs from DShield sensors. The experiment focused on capturing activity from actors or bots that successfully logged into these sensors, specifically recording the various commands executed post-login. These collected TTY logs are then parsed and transmitted daily to the DShield SIEM for correlation with other…

artificial intelligence

SECURITY AFFAIRS AI-CYBERSECURITY NEWSLETTER ROUND 2

AI agents have been observed attempting SQL injection attacks while searching government data, with investigators successfully tracing an AI agent's path from a research task to reconnaissance activities. This comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added several vulnerabilities to its Known Exploited Vulnerabilities catalog, including flaws in Zammad…

nation-state

Trump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Force

President Trump has reportedly named National Intelligence Director Jay Clayton to lead a newly established federal task force focused on artificial intelligence. This development follows a recent gathering at the White House where the President met with leading executives from various AI companies.