---
title: "Zammad GmbH Zammad — CVE-2026-102489"
description: "A remote code execution flaw affects Zammad GmbH Zammad. Apply the vendor’s patch. It is being actively exploited: patch now."
canonical: https://inyourgeek.com/en/failles-de-securite/2026-10-02-cve-2026-102489
type: faille-de-securite
author: "Sébastien Soulier"
publisher: "InYourGeek"
language: en
datePublished: 2026-10-02
dateModified: 2026-10-02
---
# Zammad GmbH Zammad — CVE-2026-102489

A remote code execution flaw affects Zammad GmbH Zammad. Apply the vendor’s patch. It is being actively exploited: patch now.

## What to do

Check the vendor advisory for the fixed version. This flaw is being actively exploited: patch now.

| Fact | Value |
| --- | --- |
| Ecosystem | Application software |
| Class | Remote code execution |
| CVE | CVE-2026-102489 |
| Published on | October 2, 2026 |
| Severity | Critical |

## Sources

- [CISA KEV — CVE-2026-102489](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) — CISA Known Exploited Vulnerabilities
- [NVD — CVE-2026-102489](https://nvd.nist.gov/vuln/detail/CVE-2026-102489) — NVD

---

Equivalent HTML page : https://inyourgeek.com/en/failles-de-securite/2026-10-02-cve-2026-102489
Published by InYourGeek — https://inyourgeek.com/en/a-propos
Method and safeguards : https://inyourgeek.com/en/methode
Full register : https://inyourgeek.com/en/failles-de-securite
