CVE-2026-102489: Zammad Session Fixation Leads to RCE – Patch Now
CISA confirms active exploitation of CVE-2026-102489 in Zammad, a session fixation vulnerability enabling remote code execution.
- Attackers are actively exploiting Zammad session fixation to achieve remote code execution.
- Zammad GmbH Zammad software is vulnerable, potentially affecting installations with internet exposure.
- Apply vendor-provided mitigations immediately and ensure compliance with CISA BOD 26-04.