Cyber Threat Brief — October 3 2026

⚠️ This report is AI-generated. Always validate findings.

1. Zammad session hijack to root — CVE-2026-102489 / CVE-2026-102490

TL;DR: CISA added the Zammad session-hijack and local-root pair to KEV after DIVD confirmed the chain was used in its own breach. Inventory self-hosted Zammad, keep the logs, and move exploitable 6.x hosts to 7.2.0 or take them offline before the KEV due date of 2026-10-05.

What’s New:

  • KEV catalog 2026.10.02 (count 1733) added both CVEs on 2026-10-02. Due date is 2026-10-05. Forensic triage is Yes. Ransomware use is Unknown.
  • DIVD case DIVD-2026-00015 says CVE-2026-102489 is a session hijack that runs code as the zammad user. It is exploitable on 6.3.0–6.5.4. The same code is present on 7.0.0–7.1.3 but is not exploitable there.
  • CVE-2026-102490 lets the local zammad user become root. DIVD lists 1.5.0 through 7.1.0-alpha. Zammad says this bug is not remote by itself and that a confirmed fix is still in progress. Their current ask is 7.2.0, which hardens the session-hijack bug.
  • DIVD’s log script flags ERROR lines that contain session material. No Nuclei, Metasploit, or Vulhub PoC was found.

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
CVE-2026-102489 on Zammad 6.3.0–6.5.4 (session hijack to code execution as user zammad). Also present, not exploitable, on 7.0.0–7.1.3. KEV due 2026-10-05 (forensic triage Yes). Vendor interim build 7.2.0.Vulnerable app / KEVT1190 / T1563Package inventory / zammad version or image tagList every self-hosted Zammad version. If it is 6.3.0–6.5.4, upgrade to 7.2.0 or take the instance offline before 2026-10-05. Copy logs before you change the host.
CVE-2026-102490, local zammad user to root, DIVD range 1.5.0 through 7.1.0-alpha. No confirmed fixed build. Vendor says it is not exploitable remotely on its own.Local privilege escalation / KEVT1068Host inventory / EDR user fieldTreat any host that already runs code as zammad as exposed to root via CVE-2026-102490 until Zammad publishes a fix. Prefer 7.2.0 now, and plan a rebuild if the log hunt below hits.
Log string "Cookie"=>" inside lines matching ERROR -- :Session leak / exploit traceT1190/var/log/zammad and /var/log/nginx (production.log, websocket.log, railsserver.log, scheduler.log, nginx access/error, including .gz)Preserve those trees, then zgrep -En 'ERROR -- :.*"Cookie"=>"' them. A hit means session material leaked into an error. Investigate before you trust the host.
Log string @clients={ inside lines matching ERROR -- :Session leak / exploit traceT1190/var/log/zammad and /var/log/nginx (same files as the cookie string, including .gz)zgrep -En 'ERROR -- :.*@clients=\{' the same trees. Treat a hit the same as the cookie string: assume the session store was exposed.
Linux user zammad as parent of /bin/sh or /bin/bashProcess behaviorT1059.004Sysmon 1 / auditd execve / EDR processAlert when user=zammad starts Image /bin/sh or /bin/bash. The Rails/Puma workers should not spawn an interactive shell.
Linux user zammad with effective UID 0Privilege changeT1068auditd / EDR (user vs euid)Alert when real user zammad executes with euid 0. That is the local half of CVE-2026-102490. Isolate the host if it fires.
Internet-reachable Zammad HTTP or HTTPSExposureT1190Firewall / external scan / reverse proxyRemove public access to self-hosted Zammad until the version is 7.2.0 or newer and the log hunt is clean. Hosted Zammad cloud was not named in the DIVD case.

Detection

SourceRuleGap
Splunk ESCUNone — verifiedWeb Servers Executing Suspicious Processes needs dest_category=web_server plus whoami, ping, iptables, wget, service, or curl. It misses the cookie/@clients={ error lines and a zammad euid change.
ElasticNone — verifiedPotential Root Effective Shell from Non-Standard Path via Auditd requires process.args:-p and an executable outside /bin and /usr/bin. A root shell from a normal path misses.
SigmaNone — verifiedLinux Webshell Indicators parents are httpd, nginx, apache2, node, caddy, or Tomcat Java, not Puma or Ruby. No emerging-threat rule names these CVEs.

Hunt hint: Copy /var/log/zammad and /var/log/nginx before you upgrade. Run DIVD cve-2026-102489_ioc_check_script_v2.sh, or the two zgrep commands in the table. Then hunt user=zammad starting /bin/sh or /bin/bash, and any exec where that user has euid 0. A hit means treat the host as root-compromised: rebuild it and rotate mailbox, database, and API secrets that lived on it. Move 6.3.0–6.5.4 to 7.2.0 or take it offline before 2026-10-05.

Sources: CISA KEV alert · DIVD-2026-00015 · DIVD-2026-00014 · DIVD IoC script · Zammad community · Sysdig · severitydaily on X


Status Updates

  • CVE-2026-104286 (FortiMail): KEV due TOMORROW 2026-10-04; forensic triage Yes. Keep /data/etc/ld.so.preload, liblog.so, webconsole, mailservice, and archive234 hunts. Fixed builds are still upcoming. Oct 2 brief.
  • CVE-2026-76504 (Cisco Catalyst SD-WAN Manager): KEV due TODAY 2026-10-03; forensic triage Yes. Confirm fixed builds and keep hunting URI-encoded j_security_check. Oct 1 brief.
  • CVE-2026-86950 (Apple CoreGraphics): KEV due was 2026-10-02; forensic triage Yes. Confirm iOS/iPadOS 26.7.1, Tahoe 26.7.1 (25G241), Sequoia 15.8.1 (24H32). Sep 29 brief.
  • CVE-2026-88771 (Citrix NetScaler): KEV due was 2026-09-30. No new CVE confirmed today. Keep LevelBlue sec_monitor / .local_journal and Mandiant WHIPSHOT/SLAPSHOT hunts. Oct 1 brief.
  • CVE-2026-88772 (Citrix NetScaler DTLS): KEV due was 2026-09-30. Confirm fixed builds. DTLS-off is temporary only for this CVE. Sep 28 brief.
  • GHSA-qx49-fqc8-xw99 (MCP Python SDK OAuth): No material change. Keep mcp ≥1.30.0 / ≥2.2.0 and issuer= on unattended providers. Sep 29 brief.
  • CVE-2026-65660 (SharePoint): KEV due was 2026-09-28. Confirm fixed builds and sphealth.aspx hunts. Sep 26 brief.
  • CVE-2026-67279 (MikroTik): KEV due was 2026-09-28. Confirm RouterOS ≥6.49.21 / ≥7.23.4 / ≥7.24.2. Sep 06 brief.
  • CVE-2026-87902 (WordPress): KEV due was 2026-09-28. Confirm WP ≥7.1.2. Sep 24 brief.
  • Carbonato / CVE-2026-62062 (Elementor): No material change. Keep TCP/2375, GH0ST/SOUL.md, and elementor/v1/events/ hunts. Elementor ≥4.3.2. Sep 28 brief.