FR
live
tag

#divd

Two Zammad zero-days hand attackers root access, exploited against disclosure institute DIVD

A chain of two Zammad flaws — session hijacking followed by privilege escalation to root — was exploited against the Dutch Institute for Vulnerability Disclosure on 21 September 2026 and added to CISA’s KEV catalog on 2 October. Move your Zammad instances to version 7 and treat any exposed instance as potentially compromised, because patching alone does not remove an attacker’s persistence.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss