Zammad GmbH (GitHub security advisories)
zammad-github-advisories · A · candidate
https://github.com/zammad/zammad/security/advisories
Added 2026-10-10: Zammad stopped publishing advisories on zammad.com in April 2026 and now publishes them as GitHub security advisories; the listing reads with `extract` and showed the 7.2.2 root-escalation fix (GHSA-p97w-927q-8vxq, 2026-10-08) and two critical advisories of 2026-10-06. Cited as the primary of a published update. The advisory text carries no CVE id, so map it through DIVD's CNA record or `bsi-csaf`. Reliability A (vendor first-party).
Cited in 65 entries
Citation cadence
Citation days per ISO week (23 weeks of coverage span, total 49).
- CVE-2026-21589, Atlassian Data Center: unauthenticated arbitrary file access in every version of eight self-managed products, patch or take them off the internet (CVSS 4.0 9.3)2026-10-06
- CVE-2026-102489 / CVE-2026-102490, Zammad helpdesk: a session-hijack remote code execution and a zammad-to-root escalation, both reported exploited since 21 September; 7.2.2 fixes the root flaw on DEB and RPM installs2026-10-02
- Kiteworks (formerly Accellion) tells customers worldwide to shut down after 'credible' law-enforcement intelligence of an imminent attack, then publishes fixes including an unauthenticated chain to root in its Email Protection Gateway (CVE-2026-54154, CVSS 10.0)2026-09-26
- CVE-2026-87902, WordPress Core: unauthenticated page-template path traversal to conditional remote code execution, weaponised within a day (CVSS4.0 9.2)2026-09-24
- CVE-2026-93616, Check Point Security Management: pre-authentication path traversal to arbitrary script execution, exploited as a zero-day, with attacks observed on 2026-07-23 (CVSS 9.8)2026-09-23
- CVE-2026-66804, Windows Cross Device Service: a dangling COM registration reaches SYSTEM privilege escalation, and Google Project Zero publishes a general method to hunt for others2026-09-22
- The Gentlemen's open-directory attack toolchain: mounting a victim's own VHDX backup files to pull ntds.dit and SAM offline, then chunked-rclone exfil to Wasabi2026-09-21
- CVE-2026-85706, GitLab CE/EE: unauthenticated path traversal in the repository commits API reads arbitrary server files, and honeypots caught exploitation attempts one day after the patch (CVSS 10.0)2026-09-12
- CVE-2026-84869, ConnectWise ScreenConnect: a missing file-transfer authorization check lets an active remote session push and auto-run files on the Host, and Huntress traced worm-like exploitation back to 20 August, weeks before any patch existed (CVSS 9.9)2026-09-12
- CVE-2026-63219 / CVE-2026-58400, GeoNetwork opensource: chained unauthenticated formatter upload plus unsafe Saxon XSLT processing reaches unauthenticated RCE (CVSS 8.6 / 9.1)2026-09-05
- Coder's Cloudflare-fronted Terraform module registry was compromised for 14 hours, serving trojanized modules that harvested cloud, CI/CD and AI-tooling credentials2026-09-04
- CVE-2026-0768, Langflow: a code-injection RCE patched since January sees renewed mass exploitation, harvesting AWS and OpenAI credentials from environment variables2026-09-03
- AI infrastructure as the new control plane: Microsoft confirms three separate intrusions against a LiteLLM gateway, a RAGFlow deployment and a Kestra orchestration environment, converging on credential theft and persistence, with compute monetisation in two of the three2026-08-31
- CVE-2026-60004: Gitea's diffpatch endpoint turns an attacker-supplied patch into a live Git hook, giving command execution as the service account; KEV-listed after miner deployment2026-08-30
- isolated-vm sandbox escape (GHSA-864f-rcv7-6rh4): a TOCTOU type-confusion in ExternalCopy's transferList marshaling breaks the V8 Isolate guest/host boundary, the sandbox underneath a wide range of AI-agent and low-code automation platforms2026-08-28
- Linux kernel IPv6 UDP fraggap accounting bug (CVE-2026-53362) added to CISA KEV, an unprivileged local heap overflow via MSG_SPLICE_PAGES, no exploitation narrative published2026-08-28
- CVE-2026-64849, MLflow: the SSRF guard resolves the webhook host and then throws the answer away, so one redirect turns an unauthenticated tracking server into a reader of its own cloud credentials2026-08-20
- CVE-2025-62593; Ray's dashboard is defended against browsers by a User-Agent string check, and CISA now records the DNS-rebinding bypass as exploited2026-08-18
- GeoServer CVE-2026-76904: an unauthenticated SQL injection in the jsonArrayContains filter was exploited within hours of disclosure, before a patch existed, and NCSC-CH put it in front of Swiss operators2026-08-15
- ShieldBreak, a public proof-of-concept defeats Microsoft's July fix for the RoguePlanet Defender flaw, claims 100% reliability where the original was a coin flip, and now covers Windows Server 20252026-08-12
- CVE-2026-64638 (XSS2Shell), WordPress Core: a sanitiser disagreement on the login screen chains through DOM clobbering and a JSONP callback into administrator-minted Application Passwords and plugin upload2026-08-10
- Wazuh 4.14.6, two cluster-protocol paths to root that bypass the CVE-2026-25770 fix, a DAPI deserialization RCE, and a pre-auth stack overflow on the enrollment port2026-08-10
- Linux kernel bridge STP timer use-after-free, a control-flow hijack primitive with a published exploit, no CVE, and no confirmed stable backport2026-08-10
- Coding-agent CI harnesses broke on the same trust boundary three different ways, and the two findings that matter most carry no CVE at all2026-08-10
- Metabase CVE-2026-72898: an unauthenticated SQL-injection zero-day gave attackers administrator access to BI instances, exploited since at least 3 August, fifteen downstream victims confirmed2026-08-09
- Traefik 3.7.10 / 3.6.25 / 2.11.54, a route identity built by joining names with hyphens lets one Kubernetes namespace silently take over another's traffic on a shared Gateway2026-08-05
- Bouncy Castle for Java 1.85, 32 CVEs published three weeks after the silent fix: three certificate-validation bypasses and a static Diffie-Hellman key-recovery flaw rated critical2026-08-03
- CVE-2026-66066, Ruby on Rails Active Storage: an unauthenticated image upload reaches arbitrary file read through libvips' unfuzzed loaders, exposing every application secret (CVSS 4.0 9.5)2026-07-31
- CVE-2026-59726 (RufRoot), Ruflo's MCP bridge took unauthenticated tool calls on all interfaces, and the memory it poisons is not cleaned up by the patch (CVSS 10.0)2026-07-30
- CVE-2025-15467, Siemens Desigo CC: a vendored OpenSSL CMS parsing overflow gives pre-auth code execution, and the V7 family still has no fix (CVSS 9.8)2026-07-29
- CVE-2026-16723, Alibaba fastjson 1.2.68–1.2.83: remote code execution under stock defaults in Spring Boot fat-JARs, exploited in the wild with no 1.x patch2026-07-27
- TA458 / Operation RoundPress: a running supply of half-click webmail zero-days adds a fresh SOGo flaw (CVE-2026-8496)2026-07-25
- CVE-2026-42533, nginx / NGINX Plus: PCRE capture-clobber pre-auth heap overflow, researcher demonstrates RCE beyond F5's DoS-only framing (CVSS 9.2)2026-07-20
- Moodle local_o365 plugin: unverified JWT signature on the Teams SSO endpoint lets anyone authenticate as any user (CVE-2026-54733)2026-07-18
- CVE-2026-61500, Rejetto HFS < 3.2.1: predictable session-signing PRNG lets an unauthenticated attacker forge admin sessions to RCE (CVSS 9.3)2026-07-13
- PraisonAI agent framework: three CVEs, unsandboxed LLM code execution, tool-call RCE, and vector-store DDL injection2026-07-11
- Git commit-signature malleability mints a second "Verified" GitHub commit with a different hash, defeating hash-based blocklists2026-07-09
- GhostApproval (CVE-2026-12958, CVE-2026-50549), symlink + confirmation-UI misrepresentation lets a malicious repo write outside six AI coding assistants' workspace sandbox2026-07-09
- CVE-2026-53359, Linux KVM/x86 "Januscape": shadow-MMU use-after-free enables guest-to-host VM escape on Intel and AMD2026-07-09
- CVE-2026-59509, cve-search: unauthenticated /fetch_cve_data parameter manipulation exposes admin credential hashes (CVSS 9.2)2026-07-05
- CVE-2026-34038, Coolify: authenticated command injection to RCE and secrets exfiltration (CVSS 9.9)2026-07-03
- CVE-2026-56447, CVE-2026-56446, CVE-2026-56425, CVE-2026-56424, CVE-2026-56423, CVE-2026-56422, MISP 2.5.42: two site-admin RCE paths plus Azure-AD auth and broken-access-control hardening2026-06-25
- CVE-2026-20896: Gitea's official Docker image trusted the reverse-proxy login header from any source, so where reverse-proxy authentication is enabled anyone can impersonate any user2026-06-23
- CVE-2026-52806, Gogs self-hosted Git server: argument injection to OS command execution (BSI critical batch)2026-06-20
- Mautic 7.1.2 / 6.0.9, seven authenticated flaws, including two post-auth RCE paths (SSTI and path-traversal-to-PHP-RCE), an SSRF and an API authorization bypass2026-05-31
- CVE-2026-48710 "BadHost", Starlette (FastAPI / vLLM / LiteLLM / MCP SDK): Pre-Auth Auth Bypass via Malformed Host Header2026-05-30
- FortiClient EMS CVE-2026-35616 + EKZ Infostealer kill chain2026-05-29
- CVE-2026-44939 (+ CVE-2026-41052, CVE-2026-41053), SUSE Rancher: command injection on cluster import, PSA label privilege-escalation, GitHub-App over-inclusive team membership2026-05-29
- CVE-2026-44848 & CVE-2026-44849, Portainer CE: Docker plugin endpoints unguarded; Swarm-service security checks bypassed (CVSS 9.4)2026-05-29
- CVE-2026-32996 & CVE-2026-32997, Veeam Backup & Replication KB4852: LPE in Windows Agent, arbitrary file write in Linux appliance2026-05-29
- Nx Console / TanStack / DAEMON Tools supply-chain cascade lands three CISA KEV entries2026-05-28
- CVE-2026-35087 / CVE-2026-35089 / CVE-2026-35090, Slican PBX telephony exchanges, triple pre-authentication admin bypass (CERT Polska)2026-05-28
- CVE-2026-5426, Digital Knowledge KnowledgeDeliver LMS: pre-shared ASP.NET machineKey enables ViewState deserialization RCE, exploited as a zero-day2026-05-26
- Sparx Enterprise Architect / Pro Cloud Server, five-CVE chain (pre-auth SQL injection + WebEA race-condition RCE), public PoC, no vendor patch2026-05-20
- n8n prototype-pollution chain (CVE-2026-42231 et al.): authenticated-to-RCE on a workflow-automation platform that Swiss/EU agencies increasingly stand up as their integration bus2026-05-19
- CVE-2026-42231 / -42232 / -44789 / -44790 / -44791, n8n self-hosted automation: chained prototype-pollution and injection flaws enabling authenticated-to-RCE plus a Git-node arbitrary file read2026-05-19
- BigBlueButton bbb-web < 3.0.21 / < 3.0.23, three flaws in EU education and government virtual-classroom platform: weak session-token randomness, API checksum bypass, SSRF2026-05-19
- CVE-2026-45691, Nextcloud Server / Enterprise Server: 2FA bypass on WebDAV via pre-authenticated session token reuse2026-05-15
- The Gentlemen RaaS, backend "Rocket" database leaked (16.22 GB), Check Point analysis exposes operator handles, ZeroPulse C2 internals, 1,570+ victims, decryptor published on GitHub2026-05-14
- FamousSparrow Three-Wave Intrusion of an Azerbaijani Energy Operator: ProxyNotShell Re-exploitation and a Wave-1 DLL-Sideload Loader That Overrides Two Hamachi Exports to Defeat Sandbox Analysis2026-05-14
- + 5 earlier entries