2026-10-02HIGHexploitedTwo Zammad zero-days breached the Dutch DIVD; the national CERT says both are exploited, the root-escalation one unfixed
Zammad, unauthenticated code execution (CVSS 4.0 8.7, 9.4 chained with CVE-2026-102490), exploited in the DIVD breach
cve · CVE-2026-102489
Coverage
1
first 2026-10-02 → last 2026-10-02
Latest activity
2026-10-02
Two Zammad zero-days breached the Dutch DIVD; the national CERT says both are exploited, the root-escalation…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, technology · regions: europe, dach
Sources cited
5
2 hosts
Action items (2)
Do-now tasks recorded on the entries about CVE-2026-102489, newest first. Check the date before acting on an older one.
- Find every self-hosted Zammad instance, copy its application and network logs before changing anything, upgrade to Zammad 7 (or take it offline if it cannot be upgraded), and run DIVD's log-check script against the logs for the code-execution flaw.2026-10-02CVE-2026-102489 +1
- Until a fix for CVE-2026-102490 is confirmed, keep Zammad off the internet or behind an authenticating reverse proxy or VPN and segment the ticket host from other internal services.2026-10-02CVE-2026-102489 +1
Defender insights
What each entry about CVE-2026-102489 tells a defender to do, newest first.
Detection
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (2 across 2 tactics)
2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- Privilege EscalationExploitation for Privilege Escalation
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-10-02/zammad-cve-2026-102489-102490-exploited-divd-breach · ATT&CK page ↗
Privilege Escalation TA0004
T1068Exploitation for Privilege Escalation×1
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.
Evidence: 2026-10-02/zammad-cve-2026-102489-102490-exploited-divd-breach · ATT&CK page ↗
Entries about Zammad, unauthenticated code execution (CVSS 4.0 8.7, 9.4 chained with CVE-2026-102490), exploited in the DIVD breach (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Zammad×1
- Zammad, privilege escalation (CVSS 4.0 8.5, 9.4 chained with CVE-2026-102489), exploited in the DIVD breach×1
Where this entity is cited
Source distribution
- csirt.divd.nl4 (80%)
- ncsc.nl1 (20%)
External references
All cited sources (5)
- ncsc.nlprimaryNCSC-NLhttps://www.ncsc.nl/alerts/actief-misbruik-van-zeroday-kwetsbaarheden-in-zammad-update-nu
- csirt.divd.nlDIVD CSIRT (case DIVD-2026-00015)https://csirt.divd.nl/DIVD-2026-00015
- csirt.divd.nlDIVD CSIRT (case DIVD-2026-00014)https://csirt.divd.nl/cases/DIVD-2026-00014/
- csirt.divd.nlDIVD CSIRT (CVE record)https://csirt.divd.nl/cves/CVE-2026-102489
- csirt.divd.nlDIVD CSIRT (CVE record)https://csirt.divd.nl/cves/CVE-2026-102490