CISA Adds Two Known Exploited Vulnerabilities to Catalog

Summary

CISA has added two new vulnerabilities, CVE-2026-102489 and CVE-2026-102490, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. These vulnerabilities, related to Zammad GmbH's Zammad software, pose significant risks and are frequent attack vectors for malicious actors. The article also references Binding Operational Directive (BOD) 26-04, which mandates federal agencies to prioritize remediation of KEV-listed vulnerabilities.

IFF Assessment

FOE

The addition of actively exploited vulnerabilities to CISA's KEV catalog indicates that these flaws are being used in real-world attacks, posing a direct threat to organizations.

Severity

9.8 Critical

CISA KEV: Listed as actively exploited. Federal patch due: October 05, 2026. Known ransomware use: Unknown.

Defender Context

Organizations, especially federal agencies, must prioritize patching and mitigating the two newly added Zammad vulnerabilities as they are actively being exploited. This highlights the importance of continuous vulnerability scanning and timely patching to prevent compromise, particularly for publicly exposed assets.

Read Full Story →