CISA Flags Two Actively Exploited Zammad Vulnerabilities
In short: CISA added two Zammad vulnerabilities to its Known Exploited Vulnerabilities catalog after confirming active exploitation. CVE-2026-102489 is a session fixation flaw and CVE-2026-102490 involves improper privilege management in the Zammad helpdesk/customer service platform. Federal agencies must remediate under Binding Operational Directive 26-04, and CISA urges all organizations to prioritize these fixes.
This summary was generated automatically by AI from CISA Advisories's publication. It is our own text, not a copy of the original — facts, figures and quotes belong to the source, linked above and below.
What changed?
- 1CVE-2026-102489: Zammad session fixation vulnerability
- 2CVE-2026-102490: Zammad improper privilege management vulnerability
- 3Both confirmed under active exploitation and added to the KEV catalog
- 4Federal agencies required to remediate per BOD 26-04
Why it matters
Zammad is a customer service/helpdesk ticketing platform often used alongside contact-center tooling; active exploitation of session and privilege flaws could let attackers hijack support agent sessions or escalate access to sensitive customer data and ticket systems.
What it means for AI agents and contact centers
If any part of your support stack or CRM integration uses Zammad for ticketing or customer communication, check whether it's affected and apply vendor patches immediately, since session fixation and privilege escalation bugs can expose customer conversation data and agent accounts tied to your contact-center workflows.
Sources
- CISA AdvisoriesOfficialPrimary sourceOriginal article →„CISA Adds Two Known Exploited Vulnerabilities to Catalog“2 Oct 2026, 15:00Licence: US federal government work (17 U.S.C. §105) · our summary (content changed)
- Published by source
- 2 Oct 2026, 15:00
- Found by our system
- 2 Oct 2026, 23:24
- Summary generated
- 3 Oct 2026, 20:04
This article was written by AI from the original source. Facts, numbers and prices come from the source; missing values are marked “Not specified”. Legal notice, copyright and privacy