Skip to content
TrustList
News

Zammad helpdesk zero-days exploited since 21 September: upgrade to Zammad 7 or take instances offline

Editorial

By TrustList Editorial

Two Zammad flaws, CVE-2026-102489 (remote code execution, 6.3.0 to 6.5.4) and CVE-2026-102490 (escalation to root, all versions, no fix yet), are exploited. DIVD and the Dutch NCSC advise upgrading to version 7 or taking Zammad offline.

About Zammad helpdesk zero-days exploited since 21 September: upgrade to Zammad 7 or take instances offline

Zammad helpdesk zero-days exploited since 21 September: upgrade to Zammad 7 or take instances offline

1 October 2026 — Two vulnerabilities in Zammad, the open-source helpdesk and customer-service ticketing system, are being exploited, and one of them has no fix yet. The Dutch Institute for Vulnerability Disclosure (DIVD) found them while investigating the breach of its own network on 21 September 2026, and published its case on 30 September. The Netherlands' National Cyber Security Centre (NCSC) issued an alert the same day, rating both the chance of abuse and the possible damage as high.

Not yet independently verified. We have not found an advisory from Zammad itself: its own advisory list and its code repository’s security page showed nothing newer than August when read on 1 October 2026. The versions and the exploitation dates come from DIVD and the Dutch NCSC. We will update this when it can be confirmed, and remove this note.

The two flaws

  • CVE-2026-102489 is a session-hijack flaw that leads to remote code execution as the zammad user. DIVD says versions 6.3.0 to 6.5.4 are vulnerable. The NCSC describes it as exploitable without logging in. DIVD adds that the flaw is also present in 7.0.0 to 7.1.3 but is not exploitable there because of environment conditions. A fix is available.
  • CVE-2026-102490 lets the local zammad user escalate to root. DIVD says it is present in every version of Zammad, including the latest alpha. There is no fix yet; DIVD says Zammad is working on one.

Chained, the two give an attacker full control of the server. The NCSC says both have been actively exploited since 21 September 2026.

What DIVD and the NCSC advise

DIVD's advice is short: upgrade to Zammad version 7, or take the instance offline. It has published a script that checks Zammad log files for indicators of compromise, and says it is scanning for exposed Zammad instances and notifying their owners. It reported the flaws to Zammad on 24 September and started notifying owners on 26 September.

The NCSC asks administrators to copy the application and network logs before installing the update. If more becomes known about how the second flaw was abused, those logs are how you will tell whether your system was attacked. For the unpatched flaw, it says to contact your supplier.

BleepingComputer, reporting DIVD's account, says the intrusion into DIVD's network was carried out by an AI agent that left explanations of its own decisions behind, which is how DIVD reconstructed the attack.

What to do

  • Find every Zammad instance you run, including test and staging copies, and note its version.
  • Copy application and network logs first, then upgrade to Zammad 7. If you cannot upgrade today, take the instance off the internet.
  • Run DIVD's log-check script from its case page and treat any hit as a breach: tickets often hold customer personal data and credentials that customers pasted in.
  • If a hosting partner runs Zammad for you, ask them in writing which version you are on and when they upgraded.
  • Watch for Zammad's own advisory and the fix for CVE-2026-102490, and apply it when it arrives.

Sources

Categories & features