{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3azammadzammad/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:zammad:zammad:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-102490"},{"id":"CVE-2026-102489"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Zammad (6.3.0 - 6.5.4)","Zammad (all current versions)","Zammad"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","rce","privilege-escalation","webserver"],"_cs_type":"threat","_cs_vendors":["Zammad"],"content_html":"\u003cp\u003eSince September 21, 2026, threat actors have been actively exploiting two zero-day vulnerabilities within Zammad, a widely used helpdesk and customer support software. The first vulnerability, CVE-2026-102489, is a critical remote code execution (RCE) flaw that allows unauthenticated attackers to execute arbitrary code on the underlying server. This issue affects Zammad versions 6.3.0 through 6.5.4 and has been addressed with a security update.\u003c/p\u003e\n\u003cp\u003eThe second vulnerability, CVE-2026-102490, allows an attacker with limited access to elevate their privileges to root, granting full system control. This vulnerability currently affects all current versions of Zammad and remains unpatched as of September 30, 2026. Given the active exploitation observed in the wild, organizations running Zammad are at high risk of complete system compromise, data theft, and persistent unauthorized access. Defenders must prioritize patching the RCE vulnerability and monitoring for unauthorized privilege escalation attempts.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify public-facing instances of Zammad.\u003c/li\u003e\n\u003cli\u003eAttacker sends specially crafted, unauthenticated HTTP requests to exploit CVE-2026-102489.\u003c/li\u003e\n\u003cli\u003eThe target Zammad server processes the malicious request, resulting in remote code execution (RCE) with the privileges of the web service account.\u003c/li\u003e\n\u003cli\u003eAttacker executes post-exploitation commands to download additional tooling or establish persistence.\u003c/li\u003e\n\u003cli\u003eAttacker leverages the limited-privilege shell to exploit CVE-2026-102490.\u003c/li\u003e\n\u003cli\u003eThe vulnerability in Zammad allows the attacker to escalate to root privileges.\u003c/li\u003e\n\u003cli\u003eAttacker gains full system control, facilitating data exfiltration, modification, or further lateral movement within the network.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities allows for unauthenticated remote code execution and full root privilege escalation on Zammad instances. This provides attackers with complete control over customer support data, communication logs, and internal credentials stored within the application. Given the nature of helpdesk platforms, compromised systems may serve as a significant pivot point for broader organizational network intrusion. Active exploitation has been confirmed since September 21, 2026, posing a critical risk to all sectors utilizing Zammad.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the security update provided by Zammad for CVE-2026-102489 immediately across all instances of versions 6.3.0 through 6.5.4.\u003c/li\u003e\n\u003cli\u003eFor CVE-2026-102490, since no patch is currently available, increase monitoring of administrative account logins and unauthorized process execution originating from the Zammad application user.\u003c/li\u003e\n\u003cli\u003eBefore applying updates, export and secure application and network logs as recommended by the NCSC to facilitate forensic analysis should evidence of exploitation be discovered.\u003c/li\u003e\n\u003cli\u003eCoordinate with IT-service providers to verify the current version of Zammad installations and assess exposure risk.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T14:14:25Z","date_published":"2026-09-30T19:45:40Z","id":"https://feed.craftedsignal.io/briefs/2026-09-zammad-zero-days/","summary":"Zammad helpdesk software is being actively exploited via two zero-day vulnerabilities, including an unauthenticated RCE (CVE-2026-102489) and an unpatched privilege escalation flaw (CVE-2026-102490).","title":"Active Exploitation of Zammad Remote Code Execution and Privilege Escalation Vulnerabilities","url":"https://feed.craftedsignal.io/briefs/2026-09-zammad-zero-days/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:zammad:zammad:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}