CPE
Zammad helpdesk software is being actively exploited via two zero-day vulnerabilities, including an unauthenticated RCE (CVE-2026-102489) and an unpatched privilege escalation flaw (CVE-2026-102490).