Cyber Threat Brief — October 3 2026
1. Zammad session hijack to root — CVE-2026-102489 / CVE-2026-102490
TL;DR: CISA added the Zammad session-hijack and local-root pair to KEV after DIVD confirmed the chain was used in its own breach. Inventory self-hosted Zammad, keep the logs, and move exploitable 6.x hosts to 7.2.0 or take them offline before the KEV due date of 2026-10-05.
What’s New:
- KEV catalog 2026.10.02 (count 1733) added both CVEs on 2026-10-02. Due date is 2026-10-05. Forensic triage is Yes. Ransomware use is Unknown.
- DIVD case DIVD-2026-00015 says CVE-2026-102489 is a session hijack that runs code as the
zammaduser. It is exploitable on 6.3.0–6.5.4. The same code is present on 7.0.0–7.1.3 but is not exploitable there. - CVE-2026-102490 lets the local
zammaduser become root. DIVD lists 1.5.0 through 7.1.0-alpha. Zammad says this bug is not remote by itself and that a confirmed fix is still in progress. Their current ask is 7.2.0, which hardens the session-hijack bug. - DIVD’s log script flags
ERRORlines that contain session material. No Nuclei, Metasploit, or Vulhub PoC was found.
Actionable Intel
| Artifact | Type | ATT&CK | Log Source | Action |
|---|---|---|---|---|
CVE-2026-102489 on Zammad 6.3.0–6.5.4 (session hijack to code execution as user zammad). Also present, not exploitable, on 7.0.0–7.1.3. KEV due 2026-10-05 (forensic triage Yes). Vendor interim build 7.2.0. | Vulnerable app / KEV | T1190 / T1563 | Package inventory / zammad version or image tag | List every self-hosted Zammad version. If it is 6.3.0–6.5.4, upgrade to 7.2.0 or take the instance offline before 2026-10-05. Copy logs before you change the host. |
CVE-2026-102490, local zammad user to root, DIVD range 1.5.0 through 7.1.0-alpha. No confirmed fixed build. Vendor says it is not exploitable remotely on its own. | Local privilege escalation / KEV | T1068 | Host inventory / EDR user field | Treat any host that already runs code as zammad as exposed to root via CVE-2026-102490 until Zammad publishes a fix. Prefer 7.2.0 now, and plan a rebuild if the log hunt below hits. |
Log string "Cookie"=>" inside lines matching ERROR -- : | Session leak / exploit trace | T1190 | /var/log/zammad and /var/log/nginx (production.log, websocket.log, railsserver.log, scheduler.log, nginx access/error, including .gz) | Preserve those trees, then zgrep -En 'ERROR -- :.*"Cookie"=>"' them. A hit means session material leaked into an error. Investigate before you trust the host. |
Log string @clients={ inside lines matching ERROR -- : | Session leak / exploit trace | T1190 | /var/log/zammad and /var/log/nginx (same files as the cookie string, including .gz) | zgrep -En 'ERROR -- :.*@clients=\{' the same trees. Treat a hit the same as the cookie string: assume the session store was exposed. |
Linux user zammad as parent of /bin/sh or /bin/bash | Process behavior | T1059.004 | Sysmon 1 / auditd execve / EDR process | Alert when user=zammad starts Image /bin/sh or /bin/bash. The Rails/Puma workers should not spawn an interactive shell. |
Linux user zammad with effective UID 0 | Privilege change | T1068 | auditd / EDR (user vs euid) | Alert when real user zammad executes with euid 0. That is the local half of CVE-2026-102490. Isolate the host if it fires. |
| Internet-reachable Zammad HTTP or HTTPS | Exposure | T1190 | Firewall / external scan / reverse proxy | Remove public access to self-hosted Zammad until the version is 7.2.0 or newer and the log hunt is clean. Hosted Zammad cloud was not named in the DIVD case. |
Detection
| Source | Rule | Gap |
|---|---|---|
| Splunk ESCU | None — verified | Web Servers Executing Suspicious Processes needs dest_category=web_server plus whoami, ping, iptables, wget, service, or curl. It misses the cookie/@clients={ error lines and a zammad euid change. |
| Elastic | None — verified | Potential Root Effective Shell from Non-Standard Path via Auditd requires process.args:-p and an executable outside /bin and /usr/bin. A root shell from a normal path misses. |
| Sigma | None — verified | Linux Webshell Indicators parents are httpd, nginx, apache2, node, caddy, or Tomcat Java, not Puma or Ruby. No emerging-threat rule names these CVEs. |
Hunt hint: Copy /var/log/zammad and /var/log/nginx before you upgrade. Run DIVD cve-2026-102489_ioc_check_script_v2.sh, or the two zgrep commands in the table. Then hunt user=zammad starting /bin/sh or /bin/bash, and any exec where that user has euid 0. A hit means treat the host as root-compromised: rebuild it and rotate mailbox, database, and API secrets that lived on it. Move 6.3.0–6.5.4 to 7.2.0 or take it offline before 2026-10-05.
Sources: CISA KEV alert · DIVD-2026-00015 · DIVD-2026-00014 · DIVD IoC script · Zammad community · Sysdig · severitydaily on X
Status Updates
- CVE-2026-104286 (FortiMail): KEV due TOMORROW 2026-10-04; forensic triage Yes. Keep
/data/etc/ld.so.preload,liblog.so,webconsole,mailservice, andarchive234hunts. Fixed builds are still upcoming. Oct 2 brief. - CVE-2026-76504 (Cisco Catalyst SD-WAN Manager): KEV due TODAY 2026-10-03; forensic triage Yes. Confirm fixed builds and keep hunting URI-encoded
j_security_check. Oct 1 brief. - CVE-2026-86950 (Apple CoreGraphics): KEV due was 2026-10-02; forensic triage Yes. Confirm iOS/iPadOS 26.7.1, Tahoe 26.7.1 (25G241), Sequoia 15.8.1 (24H32). Sep 29 brief.
- CVE-2026-88771 (Citrix NetScaler): KEV due was 2026-09-30. No new CVE confirmed today. Keep LevelBlue
sec_monitor/.local_journaland Mandiant WHIPSHOT/SLAPSHOT hunts. Oct 1 brief. - CVE-2026-88772 (Citrix NetScaler DTLS): KEV due was 2026-09-30. Confirm fixed builds. DTLS-off is temporary only for this CVE. Sep 28 brief.
- GHSA-qx49-fqc8-xw99 (MCP Python SDK OAuth): No material change. Keep
mcp≥1.30.0 / ≥2.2.0 andissuer=on unattended providers. Sep 29 brief. - CVE-2026-65660 (SharePoint): KEV due was 2026-09-28. Confirm fixed builds and
sphealth.aspxhunts. Sep 26 brief. - CVE-2026-67279 (MikroTik): KEV due was 2026-09-28. Confirm RouterOS ≥6.49.21 / ≥7.23.4 / ≥7.24.2. Sep 06 brief.
- CVE-2026-87902 (WordPress): KEV due was 2026-09-28. Confirm WP ≥7.1.2. Sep 24 brief.
- Carbonato / CVE-2026-62062 (Elementor): No material change. Keep TCP/2375,
GH0ST/SOUL.md, andelementor/v1/events/hunts. Elementor ≥4.3.2. Sep 28 brief.