Skip to content
eastbaycyber

CISA Adds 2 Known Exploited Vulnerabilities to Catalog (October 2, 2026)

Source: CISA KEV Catalog · Updated 2026-10-02

Summary

On October 2, 2026, CISA added 2 vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-102490, CVE-2026-102489. A KEV listing means CISA has evidence of active exploitation. CISA sets a remediation due date for US federal civilian agencies under its binding operational directives; any organization running the affected products should treat these as patch-now priorities.

CVE-2026-102490: Zammad GmbH Zammad Improper Privilege Management Vulnerability

Zammad GmbH · Zammad

Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489.

Federal due date
2026-10-05
Ransomware use
Unknown
Added
2026-10-02

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

NVD record

CVE-2026-102489: Zammad GmbH Zammad Session Fixation Vulnerability

Zammad GmbH · Zammad

Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490.

Federal due date
2026-10-05
Ransomware use
Unknown
Added
2026-10-02

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

NVD record

Also added to KEV in October 2026

  • October 1, 2026: CVE-2026-104286, Fortinet FortiMail (Fortinet FortiMail Path Traversal Vulnerability)

Check whether you run these products: our vulnerability scanner comparison covers tools that detect KEV-listed flaws. See also the KEV dashboard and KEV history by vendor.