Threat Brief — 2026-10-03 — Zammad KEV Chain and DTU Data Breach
Executive summary: CISA's Known Exploited Vulnerabilities catalog now includes two chainable Zammad flaws—a session fixation vulnerability and a local privilege escalation to root—that together achieve remote code execution and are confirmed exploited in the wild. Separately, the Technical University of Denmark disclosed a breach of its identity and access management system potentially exposing data belonging to up to 200,000 individuals.
Top items
- Zammad session fixation + privilege escalation chain (CVE-2026-102489KEV, CVE-2026-102490KEV) — known exploited in the wild. CISA added both to its KEV catalog. CVE-2026-102489KEV is a session fixation vulnerability in Zammad that can lead to remote code execution as the
zammaduser; CVE-2026-102490KEV allows that local user to escalate privileges to root. The two can be chained for full system compromise. This continues the Zammad KEV story first reported on 2026-09-29 by BleepingComputer (source), with the specific CVE identifiers and chaining mechanics now detailed. (src: CISA KEV)
- DTU breach exposes data of up to 200,000 people. Attackers accessed the Technical University of Denmark's identity and access management system and exfiltrated a large volume of data. The institution reports that information belonging to as many as 200,000 users may have been exposed. The specific data types compromised have not yet been fully detailed. (src: BleepingComputer)
Themes
Identity infrastructure as primary target: Both the Zammad chain (session fixation leading to RCE) and the DTU breach (direct compromise of an IAM system) illustrate sustained attacker focus on identity and access management infrastructure as a high-value entry point—consistent with the broader pattern of credential and session abuse seen across recent campaigns.
