Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
OpenClaw Launches Free Open-Source Enterprise Agent Platform for AI Agents
October 2, 2026
Exposed WordPress Backups Leak AWS and Email Credentials
October 2, 2026
Critical Zammad Flaws Let Attackers Gain Remote Code Execution
October 2, 2026
Home/CyberSecurity News/Critical Zammad Flaws Let Attackers Gain Remote Code Execution
CyberSecurity News

Critical Zammad Flaws Let Attackers Gain Remote Code Execution

Key Takeaways Two critical zero-day vulnerabilities in the Zammad helpdesk software have been identified, with evidence of active exploitation. The flaws, CVE-2026-102489 and CVE-2026-102490, could...

Emy Elsamnoudy
Emy Elsamnoudy
October 2, 2026 3 Min Read
2 0

Key Takeaways

  • Two critical zero-day vulnerabilities in the Zammad helpdesk software have been identified, with evidence of active exploitation.
  • The flaws, CVE-2026-102489 and CVE-2026-102490, could allow remote code execution and subsequent root privilege escalation.
  • Multiple Zammad versions are affected, including 6.3.0–6.5.4 for remote code execution and all versions from 1.5.0 through 7.1.0-alpha for privilege escalation.
  • A fix is currently being developed by Zammad; immediate mitigation steps include upgrading to Zammad 7 or taking vulnerable instances offline.

Critical Zammad Zero-Days Under Active Exploitation

Cybersecurity researchers have uncovered two critical zero-day vulnerabilities in the Zammad helpdesk system, which have reportedly been exploited in the wild. These flaws, tracked as CVE-2026-102489 and CVE-2026-102490, could enable attackers to achieve remote code execution (RCE) and elevate privileges to gain full control over affected servers.

Table Of Content

  • Key Takeaways
  • Critical Zammad Zero-Days Under Active Exploitation
  • Remote Code Execution via Session Hijacking
  • Local Privilege Escalation to Root
  • Chaining Attacks for Maximum Impact
  • What You Should Do

The Dutch Institute for Vulnerability Disclosure (DIVD) brought these findings to light under case DIVD-2026-00015, after their own environment was compromised. The institute’s investigation into an unrelated breach led to the discovery and analysis of these critical Zammad weaknesses.

Remote Code Execution via Session Hijacking

The first vulnerability, CVE-2026-102489, facilitates session hijacking and allows for remote code execution as the Zammad service user. DIVD confirmed that this flaw was exploited to breach their systems on September 21, 2026. This RCE vulnerability impacts Zammad versions 6.3.0 through 6.5.4.

While the issue is also present in Zammad versions 7.0.0 through 7.1.3, researchers noted that environmental factors prevent its exploitation in these newer releases.

Local Privilege Escalation to Root

The second vulnerability, CVE-2026-102490, is a local privilege escalation flaw. It affects a broad range of Zammad versions, from 1.5.0 up to and including the latest alpha builds of version 7.1.0-alpha. An attacker who has already secured access as the local zammad user can leverage this vulnerability to escalate their privileges to root, thereby gaining complete control over the compromised server.

Chaining Attacks for Maximum Impact

When combined, these two vulnerabilities create a devastating attack chain. A remote attacker could first exploit CVE-2026-102489 to execute arbitrary commands as the Zammad service account. Subsequently, they could utilize CVE-2026-102490 to escalate their access to root level. This level of access grants threat actors the ability to manipulate helpdesk data, access sensitive customer support tickets and attachments, modify user accounts, establish persistent backdoors, and expand their presence deeper into an organization’s network.

DIVD researchers meticulously analyzed and reproduced these vulnerabilities between September 22 and September 23, promptly reporting their findings to Zammad on September 24. By September 26, DIVD had initiated scans for vulnerable Zammad instances exposed to the internet, notifying affected organizations and issuing a limited disclosure while Zammad worked on developing a patch.

What You Should Do

  • Upgrade Immediately or Isolate: Given the active exploitation, organizations running Zammad should treat this as an urgent incident. DIVD advises upgrading to Zammad version 7 or taking affected instances offline until a patch becomes available. Be aware that the local privilege escalation flaw (CVE-2026-102490) still affects version 7 releases, including alpha builds.
  • Monitor Logs for Compromise: Review Zammad logs for any indicators of compromise (IoCs), such as suspicious sessions, unexpected administrative actions, unusual command executions, or modifications related to the Zammad account. DIVD has provided an IoC log-check script to assist administrators in identifying potential breaches.
  • Post-Exploitation Remediation: Since these vulnerabilities have been actively exploited, patching alone may not remove attacker persistence. If suspicious activity is detected, immediately isolate the compromised server, rotate all associated credentials and secrets, review account changes, inspect scheduled tasks and services, and conduct a thorough forensic investigation to ensure complete remediation.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachCVEExploitPatchSecurityThreatVulnerabilityzero-day

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Sony PS5 Update Patches Relapse Jailbreak Vulnerabilities

Next Post

Exposed WordPress Backups Leak AWS and Email Credentials

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Capacitor Fls-1.0.0 Flaw Exposes App Data, Native Features
October 2, 2026
Milk Dragon AiTM Kit Bypasses MFA With Real-Time OTP Relay and WebSocket Keylogging
October 2, 2026
macOS Safari History Vulnerability Exposes User Browsing Activity
October 2, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us