CISA Flags Two Zammad Session Fixation and Privilege Management Vulnerabilities (CVE‑2026‑102489, CVE‑2026‑102490) as Actively Exploited
What It Is – The Cybersecurity and Infrastructure Security Agency (CISA) added two Zammad GmbH vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog. CVE‑2026‑102489 is a session‑fixation flaw; CVE‑2026‑102490 is an improper privilege‑management issue. Both have confirmed, active exploitation in the wild.
Exploitability – Evidence of real‑world attacks exists; CISA’s KEV inclusion requires that threat actors can achieve total control of the affected asset after exploitation. No public proof‑of‑concept is needed because exploitation is already observed.
Affected Products – Zammad GmbH’s open‑source ticket‑management platform (all supported versions at the time of the advisory).
Why It Matters for Trust & Control Assurance
- Demonstrates the need for continuous vulnerability‑management evidence that maps to a single control objective: Maintain a documented, risk‑based process for timely remediation of high‑risk flaws.
- A single control that tracks KEV remediation satisfies multiple frameworks (e.g., NIST CSF 2.0, ISO 27001, SOC 2) and provides auditors with defensible proof of due diligence.
- Failure to remediate these known‑exploited flaws erodes the trust signal that enterprises rely on when evaluating a vendor’s security posture.
Recommended Actions
- Inventory all assets running Zammad and verify version details.
- Apply the vendor‑supplied patches for CVE‑2026‑102489 and CVE‑2026‑102490 immediately.
- Record remediation evidence in your control‑mapping repository to demonstrate compliance with the “timely patching” control objective.
- Update your risk‑based vulnerability‑management policy to prioritize any future KEV entries.
Source: CISA Advisory – 2026‑10‑02