Kryptovalutaticker:
sysadmin från Cyber Security News

Zammad 0-Day Vulnerabilities Exploited to Gain Remote Code Execution and Root Access

Abinaya
21 hours ago
18 Visningar
0 Kommentarer
Zammad 0-Day Vulnerabilities Exploited to Gain Remote Code Execution and Root Access

Two critical Zammad zero-day flaws, reportedly exploited against the Dutch Institute for Vulnerability Disclosure (DIVD), could allow session hijacking, remote command execution as the Zammad service user, and potential root privilege escalation. The vulnerabilities are tracked as CVE-2026-102489 and CVE-2026-102490. DIVD published the findings under case DIVD-2026-00015 after investigating a separate breach case involving its own environment. An attacker exploited CVE-2026-102489 to compromise DIVD on September 21, 2026, the session hijacking flaw affects Zammad 6.3.0–6.5.4 and can enable remote code execution as the Zammad user. The issue also exists in Zammad versions 7.0.0 through 7.1.3, according to DIVD. However,...

Läs hela artikeln hos källan.

Delta i diskussionen — kommentera, rösta och dela länkar.

Registrera
Var detta hjälpsamt?
Dela:

Kommentarer (0)

Vänligen logga in eller registrera dig för att delta i diskussionen

Inga kommentarer ännu. Bli först med att kommentera!