LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
cve recordhighexploited in the wildzero day3 of 3 cataloguesexploit reported

CVE-2026-102489

Zammad GmbH · Zammad · Zammad GmbH Zammad Session Fixation Vulnerability

· Added to CISA KEV
CVSS—
Severityhigh
Weakness—
EPSS1.4%71.5th percentile
Exploited3 KEV sources
Ransomware useUnknown
Federal fix dueOct 5, 2026
patch window

Called exploited the same day it was disclosed.

Measured from the CVE publication date to the earliest of 3 KEV catalogues that list it.

The life of this vulnerability

  1. CVE reserved
  2. CVE published1d
  3. First KEV listingsame day
  4. Last KEV listing2d
  5. Last sighting2d

Gaps are compressed to equal steps. The elapsed time is printed under each.

Which catalogues call it exploited

Sources3 of 3
Listings differ by2 d
Strongest claimconfirmed

3 catalogues list it. CIRCL aggregates the others and is shown but not counted.

Public exploitation evidence

2 public reports collected from VulnCheck and CIRCL, first on Sep 30, 2026. Each links to its original source. We have not verified them.

Description

Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490.

Required action (CISA)

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-102489

CVE-2026-102489high

Zammad Session Fixation Vulnerability Exploited Same Day as Disclosure

CVE-2026-102489, a session fixation vulnerability in Zammad GmbH Zammad, was exploited on the same day it was published. The vulnerability is now listed in multiple exploitation catalogues.

CVE-2026-102489

U.S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in Zammad GmbH's Zammad helpdesk software to its Known Exploited Vulnerabilities (KEV) catalog, mandating that federal agencies address them by October 5, 2026. These flaws, identified as CVE-2026-102489 and CVE-2026-102490, have been actively exploited in the wild, including in a recent breach of…

CVE-2026-102489critical

Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability Disclosure

The Dutch Institute for Vulnerability Disclosure (DIVD), a cybersecurity non-profit, recently disclosed that it was compromised in an attack that exploited two zero-day vulnerabilities in its Zammad helpdesk platform. The incident, detected on September 24, involved the use of what DIVD describes as an "agentic AI" to execute the attack.