Zammad helpdesk zero-days exploited since 21 September: upgrade to Zammad 7 or take instances offline
EditorialBy TrustList Editorial
Two Zammad flaws, CVE-2026-102489 (remote code execution, 6.3.0 to 6.5.4) and CVE-2026-102490 (escalation to root, all versions, no fix yet), are exploited. DIVD and the Dutch NCSC advise upgrading to version 7 or taking Zammad offline.
- Netherlands
- Cybersecurity
- Vulnerability Management
- Help Desk Software
- +1 more
About Zammad helpdesk zero-days exploited since 21 September: upgrade to Zammad 7 or take instances offline
Zammad helpdesk zero-days exploited since 21 September: upgrade to Zammad 7 or take instances offline
1 October 2026 — Two vulnerabilities in Zammad, the open-source helpdesk and customer-service ticketing system, are being exploited, and one of them has no fix yet. The Dutch Institute for Vulnerability Disclosure (DIVD) found them while investigating the breach of its own network on 21 September 2026, and published its case on 30 September. The Netherlands' National Cyber Security Centre (NCSC) issued an alert the same day, rating both the chance of abuse and the possible damage as high.
Not yet independently verified. We have not found an advisory from Zammad itself: its own advisory list and its code repository’s security page showed nothing newer than August when read on 1 October 2026. The versions and the exploitation dates come from DIVD and the Dutch NCSC. We will update this when it can be confirmed, and remove this note.
The two flaws
- CVE-2026-102489 is a session-hijack flaw that leads to remote code execution as the zammad user. DIVD says versions 6.3.0 to 6.5.4 are vulnerable. The NCSC describes it as exploitable without logging in. DIVD adds that the flaw is also present in 7.0.0 to 7.1.3 but is not exploitable there because of environment conditions. A fix is available.
- CVE-2026-102490 lets the local zammad user escalate to root. DIVD says it is present in every version of Zammad, including the latest alpha. There is no fix yet; DIVD says Zammad is working on one.
Chained, the two give an attacker full control of the server. The NCSC says both have been actively exploited since 21 September 2026.
What DIVD and the NCSC advise
DIVD's advice is short: upgrade to Zammad version 7, or take the instance offline. It has published a script that checks Zammad log files for indicators of compromise, and says it is scanning for exposed Zammad instances and notifying their owners. It reported the flaws to Zammad on 24 September and started notifying owners on 26 September.
The NCSC asks administrators to copy the application and network logs before installing the update. If more becomes known about how the second flaw was abused, those logs are how you will tell whether your system was attacked. For the unpatched flaw, it says to contact your supplier.
BleepingComputer, reporting DIVD's account, says the intrusion into DIVD's network was carried out by an AI agent that left explanations of its own decisions behind, which is how DIVD reconstructed the attack.
What to do
- Find every Zammad instance you run, including test and staging copies, and note its version.
- Copy application and network logs first, then upgrade to Zammad 7. If you cannot upgrade today, take the instance off the internet.
- Run DIVD's log-check script from its case page and treat any hit as a breach: tickets often hold customer personal data and credentials that customers pasted in.
- If a hosting partner runs Zammad for you, ask them in writing which version you are on and when they upgraded.
- Watch for Zammad's own advisory and the fix for CVE-2026-102490, and apply it when it arrives.
Sources
- DIVD CSIRT: DIVD-2026-00015, Vulnerabilities in Zammad during investigation of case DIVD-2026-00014 — 30 September 2026
- NCSC (Netherlands): Actief misbruik van zeroday-kwetsbaarheden in Zammad: update nu — 30 September 2026
- BleepingComputer: DIVD says Zammad zero-days enabled AI-driven network breach — 30 September 2026
Categories & features
- Netherlands
- Cybersecurity
- Vulnerability Management
- Help Desk Software
- Customer Service Software
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More NetherlandsThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.