
CISA flags two exploited Zammad flaws; one has no patch
Zammad, a support-ticket system, has a fix for one flaw and not the other, according to its own team. DIVD, the institute that was breached, blames an AI agent.
The US cybersecurity agency CISA added two flaws in Zammad, a customer-support ticketing system, to its Known Exploited Vulnerabilities catalog on Oct. 2. The catalog only lists flaws with evidence of use by attackers. They are CVE-2026-102489, which CISA classes as session fixation, and CVE-2026-102490, a privilege escalation.
What matters to anyone running their own Zammad:
- CVE-2026-102489 affects Zammad versions 6.3.0 to 6.5.4. In 7.0.0 to 7.1.3 it exists, but DIVD says it is not exploitable. Zammad says 7.0 and later are not affected and that 7.2.0 hardens the code.
- CVE-2026-102490 affects every version from 1.5.0 to 7.1.0-alpha. On its community forum, the Zammad team says there is no patch yet and that it will work on one "with the highest priority" once DIVD hands over the technical details.
Sources disagree on the patch status. The Dutch Institute for Vulnerability Disclosure (DIVD) case page speaks of available patches, while Security.NL reported on Oct. 1 that the second flaw remained unfixed in all versions. This article follows the vendor's own position.
DIVD, a nonprofit that reports flaws to their owners, says it found both while investigating an intrusion into its network on Sept. 21. It says an AI agent, an autonomous program that chooses its own steps, carried it out rather than a person. That is the institute's conclusion, not independently verified. It alerted Zammad on Sept. 24 and published the flaws on Sept. 30.
DIVD recommends upgrading to version 7 or taking the system offline. Zammad asks users to install 7.2.0 and, for anyone on 6.5 or older, to update immediately. DIVD also offers a script to check logs for earlier compromise. This article does not describe how the attack works.
Still pending is Zammad's security advisory for CVE-2026-102490, which its team says it will publish on GitHub. There is no data on affected installations in Mexico.



