🚨 New security alert: open-source IT service desk + customer support ticketing platform Zammad is seeing major scrutiny after Dutch researchers warned of two high-risk vulnerabilities with evidence of active exploitation. The Dutch Vulnerability Disclosure program (DIVD) reports that CISA has added both issues to the KEV (Known Exploited Vulnerabilities) catalog: • CVE-2026-102489 (Covers Zammad 6.3.0–6.5.4): session/workflow hijacking. Attackers may impersonate a legitimate user—potentially escalating to remote code execution (RCE) without needing full admin access up front. • CVE-2026-102490 (Covers Zammad 1.5.0–7.1.0-alpha): local privilege escalation. A local foothold can be turned into root-level control, accelerating lateral movement and persistence. DIVD’s advisory (DIVD-2026-00015) highlights that each flaw is already severe (8.7 and 8.5 CVSS), and chaining them could raise severity to ~9.4—meaning the real-world attack chain is even more dangerous. What to do now: upgrade to Zammad v7 ASAP, or isolate affected systems immediately. Also review logs and use DIVD’s provided log-check script + IoC validation to confirm compromise. #Zammad #CyberSecurity #KEV #VulnerabilityManagement #IncidentResponse #RCE
Want to learn more? Visit Explore the world, stay updated on travel insights and international affairs, and discover authentic stories from real life
评论
发表评论