Cyber Security· Important
CISA Flags Two Actively Exploited Zammad Vulnerabilities
CISA added two Zammad vulnerabilities to its Known Exploited Vulnerabilities catalog after confirming active exploitation. CVE-2026-102489 is a session fixation flaw and CVE-2026-102490 involves improper privilege management in the Zammad helpdesk/customer service platform. Federal agencies must remediate under Binding Operational Directive 26-04, and CISA urges all organizations to prioritize these fixes.