Open-source helpdesk software rarely lands on the federal KEV clock. Today it did, after a volunteer vuln-disclosure nonprofit said an AI agent used two Zammad zero-days to get to root in seconds.
What CISA added. Live CISA KEV JSON, catalogVersion 2026.10.02, dateReleased 2026-10-02T15:19:38.2945Z (~8:19 AM PT). New entries: CVE-2026-102490, Zammad Improper Privilege Management (CWE-269): the local zammad user can escalate to root; can be chained with CVE-2026-102489. And CVE-2026-102489, Zammad Session Fixation (CWE-384): can lead to remote code execution as the zammad user; can be chained with CVE-2026-102490. dateAdded for both: 2026-10-02. Due date: 2026-10-05. Forensic triage: Yes. Known ransomware campaign use: Unknown. Required action: apply mitigations per vendor instructions under BOD 26-04 and CISA’s forensics triage requirements, or discontinue use of the product if mitigations are unavailable. That is a mitigation deadline, not a patch deadline: for the LPE, no patch exists yet.
How the chain showed up, per DIVD. Case DIVD-2026-00014 (breach) and DIVD-2026-00015 (vuln notification): first malicious access September 21, 2026; awareness and datacenter access block September 22; reported to Zammad September 24; limited public CVE disclosure and owner notification scanning from September 26. DIVD Statement #4 (Sep 30): two zero-days allowed session hijacking, RCE, and privilege escalation from the Zammad user to root “in seconds due to the agentic part of this hack,” then access to other services and data exfiltration. Statement #5 (Oct 1): volunteer data got out, such as DIVD email addresses and possibly contact details; whose data and exactly which data is still under investigation. Actor attribution: DIVD says no link to a known public threat actor so far. Victim counts beyond DIVD: Undisclosed.
Affected ranges (DIVD-2026-00015). CVE-2026-102489 (session hijack → RCE as zammad): DIVD lists versions 6.3.0 to 6.5.4 as exploitable; also present in 7.0.0 to 7.1.3 but “not exploitable due to environment conditions.” Zammad puts exploitability at 6.5 and older. CVE-2026-102490 (LPE to root): v1.5.0 through v7.1.0-alpha, or “all versions of Zammad including the latest alpha” in DIVD’s summary. DIVD advises upgrading to Zammad version 7 or taking the instance offline; no workaround listed. The case page marks patch status “Available,” but that conflicts with Zammad’s Oct 1 update that the LPE fix is still in progress. DIVD is scanning internet-exposed instances, notifying owners, and offers a log-check script for its IoCs on the case page.
Vendor position. Zammad community statement (Oct 1): CVE-2026-102489 exploitation is only possible on 6.5 and older (end of support); 7.0 and later are not affected; the affected code was still hardened in 7.2.0. On CVE-2026-102490, Zammad first said DIVD had not sent technical details. A later update (Oct 1, 12:48 PM PT) said the details had arrived, the issue “cannot be exploited remotely on its own” (an attacker already needs server access), and Zammad is working on it. Zammad 7.2.0 does not fix the LPE: it shipped September 23, the day before DIVD reported the issues to Zammad. Zammad’s own advice is to update to 7.2.0 and watch its GitHub security advisories for the CVE-2026-102490 fix. BleepingComputer (Sep 30) cites Zammad marketing figures of >2,000 customers / 55,000 users; that is vendor marketing, not a count of exposed instances.
POV for the SOC this morning: Internet-facing Zammad on 6.x is the urgent queue: session-fixation RCE is the beachhead, the LPE is the root finish. Getting to 7.x (7.2.0 is current) closes the remote entry point per both DIVD and Zammad, but nothing closes the local root escalation yet, so anyone already on the box can still get root. KEV due Oct 5 with forensic triage. Priority: inventory self-hosted Zammad; take it off the internet or upgrade off 6.x; run DIVD’s log IoC check before you rebuild; treat a box that was exposed on 6.x as possibly rooted; assume volunteer or support-ticket data is high-value phishing bait, as in DIVD’s disclosed loss. Don’t wait for a tidy single vendor advisory: the federal clock is already running on the live KEV feed. Outside DIVD, confirmed victim count remains Undisclosed. Primaries: CISA KEV JSON 2026.10.02, DIVD-2026-00014/00015, Zammad community statement.
Desk sheet: CISA KEV catalog 2026.10.02 dateReleased 2026-10-02T15:19:38Z: CVE-2026-102489 + CVE-2026-102490; dateAdded 2026-10-02; due 2026-10-05 (mitigate or discontinue); forensic Yes; ransomware Unknown. DIVD-2026-00015: 102489 exploitable 6.3.0 to 6.5.4; 102490 v1.5.0 to v7.1.0-alpha; upgrade to 7 or take offline; exploited in DIVD breach from Sep 21. DIVD-2026-00014: agentic-AI assessment; volunteer emails out, possibly contact details; actor Undisclosed. Zammad community Oct 1: 102489 exploitable on 6.5 and older only, hardened in 7.2.0; 102490 fix in progress, no patch yet. Broad victim count: Undisclosed.
