CVE-2026-102489
Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.
- Published Sep 30, 2026
- CVSS 9.4 critical
- 1.4% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
Affected software
In the news
- ⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests The Hacker News ·
- CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA ·
- ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories The Hacker News ·
- AI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit Help Net Security ·
- Zammad Zero-Days Exploited in AI-Powered DIVD Hack SecurityWeek ·
- DIVD says Zammad zero-days enabled AI-driven network breach BleepingComputer ·