An AI attack went from help desk to root in seconds. The flaws are now on CISA's list.
By Lior AharonovFounder, 7IT Solutions ·
On 2 October 2026 CISA added two Zammad flaws, CVE-2026-102489 (session fixation) and CVE-2026-102490 (privilege management), to its Known Exploited Vulnerabilities catalog. SecurityWeek reports both at CVSS 9.4, chained on 21 September against the Dutch Institute for Vulnerability Disclosure (DIVD) in an AI-driven attack that went from a hijacked session to root in seconds.
Picture what sits in your help desk: years of customer conversations, the password resets, the invoices, often the keys to other systems. Versions 6.3.0 through 6.5.4 are exploitable; 7.0.0 through 7.1.3 carry the defect, but SecurityWeek reports it cannot be exploited there.
If you self-host Zammad 6.x, upgrade to version 7 tonight or take the server offline, which is DIVD's advice. Then run the script DIVD published to check for signs of compromise, because an upgrade does not evict someone who is already in.
A help desk is the one system everyone trusts and nobody watches. That's exactly why I'd patch it first.
Lior Aharonov · my takeSources
Researched with AI tools; every fact is checked against the linked sources.