
Critical Zero-Day Vulnerability Chain Targets Zammad Helpdesk Systems
CISA has added a critical Zammad helpdesk zero-day chain (CVE-2026-102489 and CVE-2026-102490) to its KEV catalog. Attackers are chaining these flaws to achieve remote code execution and root escalation.
Encrygma is selling the entire Full Cyber Weapon Research of Critical Zero-Day Vulnerability Chain Targets Zammad Helpdesk Systems for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- Critical
- Actor Type:
- Unknown
- Geography:
- Global
- Confidence:
- Confirmed
- CVE:
- CVE-2026-102489, CVE-2026-102490
- Source:
- Rescana
- Read Time:
- 4 min
Executive Summary
On October 2, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two critical vulnerabilities affecting the Zammad open-source helpdesk system to its Known Exploited Vulnerabilities (KEV) catalog. These vulnerabilities, tracked as CVE-2026-102489 and CVE-2026-102490, are being actively exploited in the wild. Federal agencies were mandated to remediate these flaws by October 5, 2026, due to the high risk of full system compromise.
Threat Analysis
The exploitation chain was first identified following a security incident at the Dutch Institute for Vulnerability Disclosure (DIVD), where attackers leveraged these specific flaws to gain unauthorized access to internal systems. The threat actors are utilizing the vulnerabilities to bypass authentication and escalate privileges, effectively turning a standard helpdesk ticketing platform into a beachhead for deeper network penetration. The ease of chaining these exploits makes them a high-priority target for both opportunistic cybercriminals and persistent threat actors.
Technical Details
The vulnerability chain consists of two distinct flaws:
- CVE-2026-102489: A session fixation vulnerability that allows an unauthenticated attacker to hijack user sessions, potentially leading to remote code execution (RCE) as the 'zammad' service user.
- CVE-2026-102490: An improper privilege management flaw that allows a local user (or an attacker who has already achieved the 'zammad' user context) to escalate privileges to root level.
When combined, these vulnerabilities provide a direct path from an unauthenticated state to full administrative control over the underlying server infrastructure. Both vulnerabilities carry a CVSS 3.1 score of 9.8, reflecting their critical severity.
Attribution Assessment
While specific threat actor groups have not been publicly named in relation to the Zammad campaign, the methodology—targeting helpdesk software to gain initial access—is consistent with tactics used by initial access brokers (IABs) and ransomware affiliates. The incident at DIVD suggests that the attackers are sophisticated enough to monitor vulnerability research and exploit disclosures rapidly.
Implications
Organizations utilizing Zammad for customer support or internal ticketing are at immediate risk. Successful exploitation allows attackers to access sensitive customer data, internal communications, and potentially pivot into other segments of the corporate network. Given the public availability of the vulnerability details, the window for remediation is extremely narrow.
Recommendations
- Immediate Patching: Organizations must update Zammad instances to the latest patched versions provided by the vendor immediately.
- Compromise Assessment: Review system logs for unauthorized session activity or unexpected privilege escalation events dating back to late September 2026.
- Network Segmentation: Ensure that helpdesk appliances are isolated from critical internal assets to limit the blast radius of a potential compromise.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Critical FortiMail and Citrix Zero-Day Exploitation Surge: Urgent Patching Required

Critical Zero-Day Exploitation Surge: FortiMail and Zammad Under Active Attack

