Skip to content

Vulnerability

CVE-2026-102490

Zammad vulnerability catalogued in 2026 as the second of a paired set, alongside CVE-2026-102489; Zammad version 7 is the release regarded as fixed.

Current stories

security9 publishersConfirmed

DIVD traces its breach to two chained zero-days in its own Zammad helpdesk

DIVD, the Dutch volunteer disclosure group, was breached through two chained zero-days in its own Zammad helpdesk that took an attacker to root in seconds. Zammad claims over 2,000 customers, and DIVD wants every older install upgraded to version 7 or taken offline.

Perspective Coverage

9 publishers
Builder
Builder 31%
Operator
Operator 58%
Investor
Investor 11%

Reality

Evidence70
Adoption40
Hype gap+25
Incentives45
Confidence65
build1 publisherOne report

Chained Zammad CVEs took DIVD from hijacked session to root in seconds

DIVD said attackers chained two Zammad zero-days on its own internet-facing server and went from a hijacked session to root in seconds. It assessed that an AI agent was involved and says upgrading to version 7 is not a complete fix for both flaws.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+15
Incentives35
Confidence50