7IT · News

An AI attack went from help desk to root in seconds. The flaws are now on CISA's list.

By Lior AharonovFounder, 7IT Solutions ·

What happened

On 2 October 2026 CISA added two Zammad flaws, CVE-2026-102489 (session fixation) and CVE-2026-102490 (privilege management), to its Known Exploited Vulnerabilities catalog. SecurityWeek reports both at CVSS 9.4, chained on 21 September against the Dutch Institute for Vulnerability Disclosure (DIVD) in an AI-driven attack that went from a hijacked session to root in seconds.

Why it matters

Picture what sits in your help desk: years of customer conversations, the password resets, the invoices, often the keys to other systems. Versions 6.3.0 through 6.5.4 are exploitable; 7.0.0 through 7.1.3 carry the defect, but SecurityWeek reports it cannot be exploited there.

What to do

If you self-host Zammad 6.x, upgrade to version 7 tonight or take the server offline, which is DIVD's advice. Then run the script DIVD published to check for signs of compromise, because an upgrade does not evict someone who is already in.

A help desk is the one system everyone trusts and nobody watches. That's exactly why I'd patch it first.

Lior Aharonov · my take

Sources

securityactively exploitedcisa kev

Researched with AI tools; every fact is checked against the linked sources.

All 7IT news · Atom feed

Need a hand with something like this? Talk to 7IT.