CISA Adds Two Zammad Helpdesk Flaws to Its Exploited List: What Self-Hosted Users Should Do
On October 2, 2026, the US Cybersecurity and Infrastructure Security Agency (CISA) added two vulnerabilities in the Zammad helpdesk system, CVE-2026-102489 and CVE-2026-102490, to its Known Exploited Vulnerabilities catalog, which means it has evidence they have been used in real attacks. Zammad says the first flaw can only be exploited on version 6.5 and earlier, which no longer receive security updates. If your business runs its own Zammad server on an old version, it should be updated or taken offline now.
Zammad is an open-source, web-based ticketing system that companies use for customer support and internal IT requests. A helpdesk holds customer names, email conversations and attachments, so a compromised helpdesk is a data problem as much as a technical one.
Self-hosted business tools like this are easy to install and easy to forget. Keeping them patched is part of the same work as maintaining your own web applications and custom software, and it needs a named owner.
What did CISA announce about Zammad on October 2, 2026?
CISA added two Zammad entries to the Known Exploited Vulnerabilities (KEV) catalog "based on evidence of active exploitation," according to its alert dated October 2, 2026. The catalog names them as follows:
- CVE-2026-102489: Zammad Session Fixation Vulnerability.
- CVE-2026-102490: Zammad Improper Privilege Management Vulnerability.
The alert ties the catalog to Binding Operational Directive 26-04, which sets patching requirements for US Federal Civilian Executive Branch agencies. Private companies, and organizations outside the United States, are not bound by it. CISA nonetheless encourages all organizations to prioritize fixing anything in the catalog, because a KEV listing is one of the clearer public signals that a flaw is being used and not just theorized.
What are the two Zammad vulnerabilities?
The first lets an outside attacker take over a session and run code on the server; the second lets someone who already has a foothold on that server gain full administrative (root) control. That description comes from the Dutch Institute for Vulnerability Disclosure (DIVD), which found both flaws and published them as case DIVD-2026-00015.
DIVD's timeline gives discovery on September 21, 2026, notification to the vendor on September 24, and the start of internet scanning and notifications to affected organizations on September 26. DIVD states that the vulnerabilities were used to breach DIVD's own systems, which is how they came to light.
Used together, the two flaws are more serious than either alone: one gets an attacker in, the other gives them the whole machine. We are deliberately not describing how either works.
Which Zammad versions are affected?
The remotely exploitable flaw, CVE-2026-102489, affects Zammad 6.5 and earlier in practice. DIVD lists versions 6.3.0 through 6.5.4 as exploitable and says the same flawed code exists in 7.0.0 through 7.1.3 but cannot be exploited there because of differences in the runtime environment.
Zammad's security advisory, published October 5, 2026, agrees on the key point: "Exploitation is only possible on Zammad 6.5 and earlier versions," and those versions "have been out of support for some time and no longer receive security updates." Zammad adds that 7.0 and later "are not affected in practice" and that it changed the affected code anyway as a hardening step in Zammad 7.2.0.
Where the vendor and the researchers differ
The two sources are less aligned on CVE-2026-102490. DIVD describes it as present across a very wide range of versions. Zammad describes it as "a local privilege escalation vulnerability that cannot be exploited remotely on its own," says an attacker "would need access to the underlying server beforehand," and links it to a confirmed vulnerability in packager.io, the service used to build Zammad's installation packages. As of October 6, 2026, we could not confirm from either page a specific Zammad version that fully resolves this second issue, so ask your administrator to follow the vendor advisory for updates.
Is my business affected if we use Zammad?
You are at immediate risk if you host Zammad yourself, the version is 6.5 or older, and the login page can be reached from the internet. You are in a much better position if you are on version 7.0 or later, though Zammad still recommends moving to 7.2.0.
If Zammad hosts your helpdesk for you, the vendor's advisory does not give separate guidance for hosted customers; ask Zammad support directly which version your instance runs. If you have never heard of Zammad, check anyway with your IT contact: helpdesk tools are often set up by one team and unknown to everyone else.
What should a business do now?
Ask the person who manages the server to work through these steps and report back in writing:
- Confirm the exact Zammad version installed and whether it is reachable from the public internet.
- If it is 6.5 or older, update immediately, as Zammad advises. DIVD's advice is to upgrade to version 7 or take the service offline until you can.
- Move to Zammad 7.2.0 or later to pick up the hardening change, after taking a backup.
- Restrict access to the underlying server to trusted administrators only, which is Zammad's second recommendation and the main defense against CVE-2026-102490.
- Check for signs of past compromise. DIVD has published a log-checking script for this purpose on its case page.
- If there are signs of intrusion, treat it as an incident: preserve logs, change credentials and API tokens stored in the helpdesk, and get professional help before rebuilding.
If the review suggests customer data may have been accessed, breach notification duties may apply in your jurisdiction, with short deadlines in some of them. Speak to a qualified adviser; this is not legal advice.
Why were old, unsupported versions the real problem?
The exploitable versions were already out of support before these flaws were found, so there was never going to be a patch for them. The only fix is a major-version upgrade, which takes longer and is more likely to be postponed than a routine update.
This pattern is common with self-hosted tools: the software keeps working, nobody is assigned to it, and it quietly falls behind. A simple inventory of every internet-facing application, its version, its support end date and its owner prevents most of it. Our guide to software maintenance and support explains what that upkeep normally includes.
Quick answers
What is CVE-2026-102489?
CVE-2026-102489 is a session fixation vulnerability in the Zammad helpdesk system. CISA added it to the Known Exploited Vulnerabilities catalog on October 2, 2026, and Zammad says it can only be exploited on Zammad 6.5 and earlier.
Which Zammad version fixes the vulnerabilities CISA listed?
Zammad recommends updating to Zammad 7.2.0, which includes a hardening change for CVE-2026-102489. Zammad states that version 7.0 and later are not affected by that flaw in practice, and that versions 6.5 and earlier are out of support.
Is Zammad 7 affected by CVE-2026-102489?
According to both Zammad and the researchers at DIVD, the flawed code exists in Zammad 7.0.0 through 7.1.3 but cannot be exploited there because of the runtime environment. Zammad still changed the code in version 7.2.0 as a precaution.
Does a CISA KEV listing apply to private businesses?
The patching requirements linked to the CISA Known Exploited Vulnerabilities catalog bind US federal civilian agencies only. CISA encourages every organization to prioritize fixing vulnerabilities in the catalog because they are known to be used in real attacks.
Can CVE-2026-102490 be exploited over the internet?
Zammad says CVE-2026-102490 is a local privilege escalation flaw that cannot be exploited remotely on its own, because an attacker first needs access to the server. It becomes more dangerous when combined with another flaw that provides that access.
What should I do if I run an old Zammad server?
Update a Zammad 6.5 or older installation immediately, or take it offline until it can be upgraded. Then restrict server access to trusted administrators and check the logs for signs of earlier compromise.
Conclusion
CISA's October 2, 2026 addition of CVE-2026-102489 and CVE-2026-102490 confirms that Zammad helpdesks have been attacked in practice, and the exposed installations are the ones on version 6.5 or earlier that no longer receive fixes. The steps are clear: confirm your version, upgrade to 7.2.0, limit who can reach the server and check for past intrusion.
If you have a self-hosted helpdesk or other business application and nobody available to check it, you can contact Entrant Technologies and we will take a look.