Skip to content
Rota Nacional

Cyber ·

CISA adds two Zammad flaws to KEV catalog

On October 2, 2026, CISA added two Zammad vulnerabilities to the KEV catalog based on evidence of active exploitation: session fixation and improper privilege management.

On October 2, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two Zammad vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation: CVE-2026-102489, a session-fixation flaw, and CVE-2026-102490, an improper privilege-management flaw. The agency says these vulnerability types are frequent attack vectors and pose significant risks to the federal sector.

Directive BOD 26-04 requires Federal Civilian Executive Branch agencies to prioritize remediation of high-risk KEV vulnerabilities on internet-exposed assets, and sets expectations for checking whether systems were compromised. The directive applies to those agencies; CISA encourages all organizations to use risk-based vulnerability management. To verify the scope, guidance, and updates, consult CISA’s original alert and KEV catalog, then confirm the CVEs and applicable mitigations in official Zammad advisories.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free