U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-102489 (CVSS score of 9.4) Zammad GmbH Zammad... Weiterlesen: U.S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulner…
Intelligence View
⚡ tsecurity.de Intelligence
U.S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog. The U.S.…
Cyber Threat Intelligence & Forensik
ATT&CK-Navigator · IoC-Radar · Exploit-Belege
Compliance, SLA & Vendor Adherence
Advisory-Prüfung · Score-Einordnung · Fristen
NVD Primärbewertung & CISA SSVCCVE-2026-102489
NVD: AnalyzedNVD 9.8 · CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NVD-Datenstand: 02.10.2026, 17:55 UTC
Ausnutzung beobachtet: Ja — aktiv Automatisierbar: Ja Technischer Impact: Total
CISA KEV seit 02.10.2026 Frist: 05.10.2026
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discon
BSI-Warnung (Deutschland)CVE-2026-102489
Zammad: Mehrere Schwachstellen ermöglichen Ausführen von beliebigem Programmcode und Privilegieneskalation kritisch30.09.2026CISA-SSVC-Triage (vulnrichment)CVE-2026-102489
Exploitation: active (Aktiv ausgenutzt)Automatable: yes (Automatisierbar)Technical Impact: total (Vollständig)
Quelle: CISA-ADP vulnrichment · Stand 2026-10-02T16:27:26.039890Z · CISA Coordinator
Advisory Radar
Kritischer Zero-Day / Ohne Upstream-Patch
Hersteller-Sicherheitsmeldungen & Patch-Status
Handlungsempfehlung für Administratoren
Wird aktiv im Feld ausgenutzt! Kein verifiziertes Hersteller-Update gemeldet. Sofortige Quarantäne oder WAF-Virtual-Patching zwingend.
Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
-
Web Referencecsirt.divd.nl
-
Web Referencecsirt.divd.nl