RDS GoSOC AI — Field Notes AI-powered SOC + 16-framework compliance · 14-day free trial

CISA KEV Alert: Two Zammad Vulnerabilities Under Active Exploitation

Session Fixation and Privilege Escalation Flaws Demand Immediate Remediation Across Federal and Commercial Environments

Published 2026-10-03

# CISA KEV Alert: Two Zammad Vulnerabilities Under Active Exploitation

CISA has added two actively exploited Zammad vulnerabilities—CVE-2026-102489 (Session Fixation) and CVE-2026-102490 (Improper Privilege Management)—to its Known Exploited Vulnerabilities (KEV) Catalog, signaling immediate risk for any organization running the Zammad helpdesk platform.

What the Advisory Actually Says

Both vulnerabilities affect Zammad GmbH's Zammad platform, a widely deployed open-source support and ticketing system. CISA's addition to the KEV Catalog is based on evidence of active exploitation in the wild—not theoretical risk.

Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies are required to prioritize rapid remediation of vulnerabilities in the KEV Catalog. Commercial organizations should treat this directive as the gold standard for their own patch timelines.

Why This Matters Beyond Federal Networks

Support and ticketing platforms like Zammad sit at a uniquely dangerous intersection: they hold customer PII, internal escalation workflows, and privileged agent credentials. A successful session fixation attack followed by privilege escalation is a two-stage breach chain that can expose entire customer datasets.

The compliance implications are immediate and cross-framework:

Failure to act is not just a security gap—it is a documented compliance deficiency that auditors and regulators will scrutinize.

What Your Team Should Do in the Next 7–30 Days

Within 7 days:

Within 30 days:

Start Your Free Trial—Every Feature, Zero Friction

RDS GoSOC AI maps KEV alerts like this one directly to your active compliance frameworks in real time. Whether you're managing NIS2 obligations, a SOC 2 audit, or PCI DSS assessments, the platform correlates threat intelligence with control gaps and generates evidence-ready remediation guidance automatically. Start a 14-day free trial at the GoSOC platform—every paid feature is unlocked from day one, no credit card required. Once inside, open the User Guide tab to get oriented quickly, and mention Sage in any question to engage the AI assistant for framework-specific remediation walkthroughs tailored to your environment.

---

#MSP #ManagedServices #CMMC #FedRamp #CyberSecurity #SOC #SecurityOperations #MSSP #ThreatDetection #Compliance #CloudSecurity #IdentitySecurity #SecurityMonitoring #ITServices #CyberResilience #ManagedSecurity #BusinessGrowth

Start the 14-day free trial →