#Zammad
All CosmicBytez Labs articles tagged #Zammad, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-102489: Zammad Session Fixation Flaw Added to CISA KEV Catalog
CISA added CVE-2026-102489, a Zammad session fixation bug chaining to RCE as the zammad user, to its KEV catalog after active exploitation.
- Security
CVE-2026-102490: Zammad GmbH Zammad Improper Privilege Management Vulnerability
A local privilege escalation flaw lets the zammad user gain root on any Zammad instance; chainable with CVE-2026-102489, actively exploited, now in CISA KEV.
- News
ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories
This week: an AI agent chained two Zammad zero-days to root in seconds, 543,699 live secrets sat exposed on GitHub, plus an Unsloth Studio model-inspection RCE.
- News
Zammad Zero-Days Exploited in AI-Powered DIVD Hack
An autonomous AI agent chained two Zammad zero-days (CVE-2026-102489, CVE-2026-102490) to hijack sessions, gain RCE, and reach root in seconds.
- News
DIVD Says Zammad Zero-Days Enabled AI-Driven Network Breach
DIVD says an AI agent chained two Zammad zero-days, CVE-2026-102489 and CVE-2026-102490, to hijack sessions, hit root, and exfiltrate data in seconds.