Two critical vulnerabilities in the open-source Zammad helpdesk and ticketing platform can be exploited together, enabling attackers to achieve remote code execution and gain root-level control of affected servers. The Dutch Institute for Vulnerability Disclosure (DIVD) and Merlon Security discovered these vulnerabilities, tracked as CVE-2026-102489 and CVE-2026-102490, during an investigation into a breach of DIVD’s […]
Read the original article:
