Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Alje Woltjer

#14930of 57,349
19.6Total CVSS
Vulnerabilities · 2
Critical
2
PT-2026-103453
9.8
2026-09-30
Zammad · Zammad · CVE-2026-102489
**Name of the Vulnerable Software and Affected Versions** Zammad versions 6.3.0 through 6.5.4 **Description** A session hijack issue allows for remote code execution as the zammad user. This flaw was utilized in a real-world incident involving the DIVD Dutch Institute, where agentic AI automation was used to exfiltrate data. **Recommendations** Update Zammad to version 7.0.0 or later. Take the system offline to prevent exploitation.
PT-2026-103454
9.8
2026-09-30
Zammad Gmbh · Zammad · CVE-2026-102490
**Name of the Vulnerable Software and Affected Versions** Zammad (affected versions not specified) **Description** Improper privilege management allows a local `zammad` user to escalate privileges to root. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.