Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Advisory

CISA Flags Two Zammad Session Fixation and Privilege Management Vulnerabilities (CVE‑2026‑102489, CVE‑2026‑102490) as Actively Exploited

CISA added two Zammad ticket‑system flaws to its Known Exploited Vulnerabilities catalog, indicating active exploitation. Organizations must patch quickly and capture remediation evidence to satisfy cross‑framework control objectives for audit readiness.

LiveThreat™ Intelligence · 📅 October 03, 2026· 📰 cisa.gov
🟠
Severity
High
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
1 recommended
📰
Source
cisa.gov

CISA Flags Two Zammad Session Fixation and Privilege Management Vulnerabilities (CVE‑2026‑102489, CVE‑2026‑102490) as Actively Exploited

What It Is – The Cybersecurity and Infrastructure Security Agency (CISA) added two Zammad GmbH vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog. CVE‑2026‑102489 is a session‑fixation flaw; CVE‑2026‑102490 is an improper privilege‑management issue. Both have confirmed, active exploitation in the wild.

Exploitability – Evidence of real‑world attacks exists; CISA’s KEV inclusion requires that threat actors can achieve total control of the affected asset after exploitation. No public proof‑of‑concept is needed because exploitation is already observed.

Affected Products – Zammad GmbH’s open‑source ticket‑management platform (all supported versions at the time of the advisory).

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous vulnerability‑management evidence that maps to a single control objective: Maintain a documented, risk‑based process for timely remediation of high‑risk flaws.
  • A single control that tracks KEV remediation satisfies multiple frameworks (e.g., NIST CSF 2.0, ISO 27001, SOC 2) and provides auditors with defensible proof of due diligence.
  • Failure to remediate these known‑exploited flaws erodes the trust signal that enterprises rely on when evaluating a vendor’s security posture.

Recommended Actions

  • Inventory all assets running Zammad and verify version details.
  • Apply the vendor‑supplied patches for CVE‑2026‑102489 and CVE‑2026‑102490 immediately.
  • Record remediation evidence in your control‑mapping repository to demonstrate compliance with the “timely patching” control objective.
  • Update your risk‑based vulnerability‑management policy to prioritize any future KEV entries.

Source: CISA Advisory – 2026‑10‑02

📰 Original Source
https://www.cisa.gov/news-events/alerts/2026/10/02/cisa-adds-two-known-exploited-vulnerabilities-catalog ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →