On 1 and 2 October, CISA added two Zammad vulnerabilities and one Fortinet FortiMail vulnerability to its Known Exploited Vulnerabilities (KEV) catalogue, citing evidence of active exploitation.[1][2] The entries describe different attack paths: ACN and DIVD report a Zammad chain from session hijacking to root, while Fortinet describes an unauthenticated file-write flaw in FortiMail.[4][5][7] The CISA records establish a common catalogue decision, not a shared actor or campaign.[1][2] DIVD separately reports that its own network was breached through the Zammad vulnerabilities; that account does not connect the FortiMail entry to that incident.[9]
Two alerts, one catalogue update
CISA’s 2 October alert lists CVE-2026-102489, a Zammad session fixation vulnerability, and CVE-2026-102490, a Zammad improper privilege-management vulnerability.[1] The agency’s 1 October alert lists CVE-2026-104286, a FortiMail path-traversal vulnerability.[2]
The common fact is the KEV decision, not a shared actor or campaign.[1][2] CISA says the entries meet its criterion of evidence of active exploitation and notes that BOD 26-04 requires rapid remediation for relevant FCEB assets.[1][2] The same alerts make clear that the directive applies only to FCEB agencies, while CISA encourages other organisations to use the catalogue for risk-based prioritisation.[1][2]
Zammad: a reported chain from session to root
ACN reports active network exploitation and says the two vulnerabilities had already been remediated by the vendor.[4] That is ACN’s account, not proof that both fixes were available or applied across every affected installation.[4][6]
ACN describes CVE-2026-102490 as a local privilege-escalation defect that allows the zammad system user to reach root. In a chained attack, the first vulnerability supplies the local foothold and the second raises the privilege level.[4] CISA’s catalogue uses the same chain relationship in its short descriptions.[3]
DIVD separately reports that its own systems were breached through the two Zammad zero-days, allowing session hijacking, remote code execution and escalation from the zammad user to root. It says the investigation found signs of compromise and remains open.[9] This is an account of a reported Zammad incident, not evidence that the FortiMail entry belonged to the same operation.[9]
The affected-version picture needs more care than a single range in a headline. DIVD lists Zammad 6.3.0 through 6.5.4 as affected by the remote-code-execution issue, says the issue is present but not exploitable under stated environmental conditions in 7.0.0 through 7.1.3, and lists versions 1.5.0 through 7.1.0-alpha for the local privilege-escalation issue.[5]
Zammad’s public response narrows the first issue to versions 6.5 and older in practical terms, says 7.0 and later are not affected by it, and points to hardening included in 7.2.0.[6] For CVE-2026-102490, Zammad first said it had received no technical details; a later update says the details had arrived, work was under way, and the issue cannot be exploited remotely on its own.[6]
These accounts cannot be collapsed into a single fix status. DIVD recommends upgrading to version 7 or taking the instance offline, while Zammad recommends 7.2.0 and continued monitoring of its security advisories; until a current release and advisory check is completed, the fixed status and practical scope of CVE-2026-102490 remain unresolved.[5][6] Publicly exposed or unsupported installations therefore warrant urgent triage even where the version boundaries are disputed.[5][6]
FortiMail: unauthenticated file writing at the edge
CVE-2026-104286 is a different problem in a different product. Fortinet describes a path-traversal and NULL-byte-handling vulnerability that may allow an unauthenticated attacker to write arbitrary files to the underlying FortiMail system through crafted HTTP or HTTPS requests; the advisory says exploitation has been reported in the wild.[7]
Fortinet’s advisory lists FortiMail 8.0.0 to 8.0.1, 7.6.0 to 7.6.6, 7.4.0 to 7.4.8, and 7.2.0 to 7.2.9 as affected. It lists upcoming fixes for the first three branches and directs 7.2 users to move to the 7.4 branch.[7]
The current NVD record repeats the four-branch wording in its vulnerability description, but its affected-products table also lists 7.0.0 through 7.0.9 and different upper bounds for the 7.4 and 7.6 branches.[10] The Fortinet PSIRT advisory supplies the remediation scope, while the NVD discrepancy remains unresolved.[7][10] Administrators should check current vendor guidance against their inventory rather than assume the records are reconciled.[7][10]
At the time of the Fortinet advisory, the immediate workarounds were to disable Identity-Based Encryption, restrict access to the FortiMail webmail interface to trusted private networks, or block matching /ibe POST requests at a web application firewall.[7]
The independent MS-ISAC advisory describes the same public-facing GUI path and says successful exploitation could lead from arbitrary file writing to arbitrary command execution. It also confirms the four ranges in the Fortinet advisory and attributes the in-the-wild exploitation report to Fortinet.[8]
A practical triage order
For Zammad, identify the exact version and whether the service is reachable from the public internet.[5][6] DIVD advises upgrading or taking the service offline, while Zammad’s own guidance is to update to 7.2.0 and watch its advisories.[5][6] Neither recommendation should be read as proof that every branch is fixed or has identical exploitability conditions.
For FortiMail, compare every appliance with Fortinet’s current advisory, record the source and date used for the version assessment, apply the temporary IBE or network restrictions where relevant, and check the advisory’s indicators of compromise before declaring the incident closed.[7][10] The MS-ISAC guidance also recommends updates, least privilege and network segmentation, but those measures reduce impact and do not replace the vendor workaround or fixed release.[8]
Finally, treat the CISA dates as a prioritisation signal with a defined federal scope. The catalogue marks all three entries for forensic triage and lists ransomware use as unknown.[3] A KEV listing is evidence that exploitation has been observed, not proof that a particular organisation was breached; that distinction should drive the order of investigation as well as the order of patching.[1][2]
Sources
[1] CISA Adds Two Known Exploited Vulnerabilities to Catalog
[2] CISA Adds One Known Exploited Vulnerability to Catalog
[3] CISA Catalog of Known Exploited Vulnerabilities JSON feed
[4] Zammad: rilevato sfruttamento in rete delle CVE-2026-102489 e CVE-2026-102490
[5] DIVD-2026-00015 – Vulnerabilities in Zammad
[6] Zammad statement on vulnerability reports in DIVD case DIVD-2026-00015
[7] FortiGuard PSIRT FG-IR-26-175
[8] A Vulnerability in Fortinet FortiMail Could Allow for Arbitrary Code Execution