Ethical Hacking News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added Zammad GmbH vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, highlighting the growing threat of AI-driven attacks in the cybersecurity landscape. The two identified vulnerabilities can be chained together to grant an attacker root access to the system in a matter of seconds, and CISA orders federal agencies to fix the vulnerabilities by October 5, 2026. Private organizations are advised to review the catalog and address the vulnerabilities in their infrastructure to prevent exploitation of known vulnerabilities.
The US Cybersecurity and Infrastructure Security Agency (CISA) has added Zammad GmbH vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, highlighting the growing threat of AI-driven attacks.Two identified vulnerabilities, CVE-2026-102489 and CVE-2026-102490, are session fixation and local privilege escalation vulnerabilities that can be chained together to grant an attacker root access.The vulnerabilities were discovered by the Dutch Institute for Vulnerability Disclosure (DIVD), which itself was breached by the attackers using the same vulnerabilities.The attack used an AI agent to analyze the environment, chain the vulnerabilities, and gain higher privileges without human intervention.CISA orders federal agencies to fix the vulnerabilities by October 5, 2026, while private organizations are advised to review the catalog and address the vulnerabilities in their infrastructure.Zammad has over 2,000 customers and 55,000 users, and the organization is actively notifying owners of vulnerable instances and has published a script to check logs for signs of abuse.The incident highlights the importance of patching and updating software to prevent exploitation of known vulnerabilities.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently added Zammad GmbH vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, highlighting the growing threat of AI-driven attacks in the cybersecurity landscape. The two identified vulnerabilities, CVE-2026-102489 and CVE-2026-102490, are session fixation and local privilege escalation vulnerabilities, respectively, which can be chained together to grant an attacker root access to the system in a matter of seconds.
The vulnerabilities were discovered by the Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit organization of volunteer security researchers, which itself was breached by the attackers using the same vulnerabilities. The attackers exploited the vulnerabilities in Zammad, an open-source helpdesk platform used by DIVD internally, to gain unauthenticated access and eventually move to root privileges. The use of an AI agent during the attack enabled the attackers to analyze the environment, chain the vulnerabilities, and gain higher privileges without human intervention.
This incident highlights the significant threat posed by AI-driven attacks, which can be more sophisticated and difficult to detect than traditional attacks. The attackers were able to leave visible traces of their activity, which helped investigators understand what happened. However, a more careful attacker using the same approach could be harder to detect.
CISA orders federal agencies to fix the vulnerabilities by October 5, 2026, while private organizations are advised to review the catalog and address the vulnerabilities in their infrastructure. The incident also emphasizes the importance of patching and updating software to prevent exploitation of known vulnerabilities.
Zammad has over 2,000 customers and 55,000 users, and the organization is actively notifying owners of vulnerable instances and has published a script to check logs for signs of abuse. The fix is version 7, which Zammad considers safe. Users are advised to update to version 7 or take the system offline as soon as possible.
The Dutch Institute for Vulnerability Disclosure (DIVD) recently disclosed that it got breached through two zero-days in its own ticketing system. The attackers got in through Zammad, an open-source helpdesk platform that DIVD used internally. Working with Merlon Security, DIVD identified the two previously unknown vulnerabilities, tracked as CVE-2026-102489 and CVE-2026-102490.
Each vulnerability was serious on its own, but chaining them made the attack much more dangerous. The attackers could hijack sessions, run code remotely, and move from a regular Zammad account to root access within seconds. DIVD said the speed was linked to the use of an AI agent during the attack.
โWhen hackers get hacked, we deal with it in hacker style. While trying to figure out how the attackers got into our own systems, ๐๐ฒ ๐ณ๐ผ๐๐ป๐ฑ ๐๐๐ผ ๐๐ฒ๐ฟ๐ผ-๐ฑ๐ฎ๐ ๐๐๐น๐ป๐ฒ๐ฟ๐ฎ๐ฏ๐ถ๐น๐ถ๐๐ถ๐ฒ๐ ๐ถ๐ป ๐ญ๐ฎ๐บ๐บ๐ฎ๐ฑ.โ
the organization wrote on LinkedIn.
Related Information:
https://www.ethicalhackingnews.com/articles/US-CISA-Adds-Zammad-GmbH-Flaws-to-Known-Exploited-Vulnerabilities-Catalog-AI-Driven-Attacks-Pose-Growing-Threat-ehn.shtml
https://securityaffairs.com/200248/security/u-s-cisa-adds-zammad-gmbh-zammad-flaws-to-its-known-exploited-vulnerabilities-catalog.html
https://www.cisa.gov/known-exploited-vulnerabilities-catalog
https://nvd.nist.gov/vuln/detail/CVE-2026-102489
https://www.cvedetails.com/cve/CVE-2026-102489/
https://nvd.nist.gov/vuln/detail/CVE-2026-102490
https://www.cvedetails.com/cve/CVE-2026-102490/
Published: Fri Oct 2 18:47:53 2026 by llama3.2 3B Q4_K_M