A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that can expose active users’ session cookies and enable remote code execution (RCE) as the Zammad operating system user. This flaw was reportedly exploited during the September breach of the Dutch Institute for Vulnerability Disclosure... Weiterlesen: PoC Exploit Released for Zammad Vulnerability Enabling Session Hijack…
Intelligence View
⚡ tsecurity.de Intelligence
PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that can expose active users’ session cookies and e…
Cyber Threat Intelligence & Forensik
ATT&CK-Navigator · IoC-Radar · Exploit-Belege
Compliance, SLA & Vendor Adherence
Advisory-Prüfung · Score-Einordnung · Fristen
NVD Primärbewertung & CISA SSVCCVE-2026-102489
NVD: AnalyzedNVD 9.8 · CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NVD-Datenstand: 03.10.2026, 04:17 UTC
Ausnutzung beobachtet: Ja — aktiv Automatisierbar: Ja Technischer Impact: Total
CISA KEV seit 02.10.2026 Frist: 05.10.2026
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discon
BSI-Warnung (Deutschland)CVE-2026-102489
Zammad: Mehrere Schwachstellen ermöglichen Ausführen von beliebigem Programmcode und Privilegieneskalation kritisch30.09.2026CISA-SSVC-Triage (vulnrichment)CVE-2026-102489
Exploitation: active (Aktiv ausgenutzt)Automatable: yes (Automatisierbar)Technical Impact: total (Vollständig)
Quelle: CISA-ADP vulnrichment · Stand 2026-10-02T00:00:00+00:00 · CISA Coordinator
Advisory Radar
Kritischer Zero-Day / Ohne Upstream-Patch
Hersteller-Sicherheitsmeldungen & Patch-Status
Handlungsempfehlung für Administratoren
Wird aktiv im Feld ausgenutzt! Kein verifiziertes Hersteller-Update gemeldet. Sofortige Quarantäne oder WAF-Virtual-Patching zwingend.
Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
-
Web Referencecsirt.divd.nl
-
Web Referencecsirt.divd.nl
-
Web Referencezammad.com
-
Web Referencecommunity.zammad.org
Intelligence Digest — kostenlos Täglich die wichtigsten Security-News · jederzeit abbestellbar