On 2 October 2026, CISA, a US government agency, added two bugs to its Known Exploited Vulnerabilities (KEV) catalog. It said it has evidence of active attacks. Both are in Zammad, from Zammad GmbH. CVE-2026-102489 is a session fixation flaw. CVE-2026-102490 is an improper privilege management flaw.
The notice gives only IDs, vendor, product and flaw type. It does not say who is attacking, how many systems are hit, or which versions are affected. It also does not say if either bug gives full control or if any Zammad system is exposed. In general, session fixation lets an attacker fix a user's session ID before login, then reuse it. Improper privilege management lets a user do more than their role allows. These are general descriptions, not CISA details on these two bugs.
CISA's directive BOD 26-04 tells US federal civilian agencies to fix KEV bugs first on exposed assets that give total control. It also expects agencies to check for compromise before patching. CISA does not say whether these two bugs meet that bar. Teams running Zammad can ask: is it reachable from the internet, who holds admin roles, and how would we spot misuse? A KEV listing is a reason to ask, even with few details.