Zammad GmbH Zammad Improper Privilege Management Vulnerability (CVE-2026-102490) is being actively exploited, CISA warns
CISA added CVE-2026-102490 (Zammad GmbH Zammad) to its Known Exploited Vulnerabilities catalog on October 2, 2026, which means there is reliable evidence of exploitation in the wild. Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489.
CISA lists this as exploited in the wild. Unpatched Zammad systems are exposed to active attacks now.
Treat this as an emergency.
