Executive Summary
CISA has added two known exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2026-102489 concerning a Zammad GmbH Session Fixation Vulnerability, and CVE-2026-102490 concerning a Zammad GmbH Improper Privilege Management Vulnerability. These vulnerabilities are considered frequent attack vectors for malicious cyber actors targeting federal enterprise systems.
Binding Operational Directive (BOD) 26-04 establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. This directive mandates that federal agencies prioritize rapid remediation for high-risk vulnerabilities listed in the KEV Catalog, especially those affecting publicly exposed assets that grant total post-exploitation control. The directive also requires agencies to verify whether threat actors compromised a system before applying a patch.
CISA encourages all organizations to adopt risk-based vulnerability management and prioritize the remediation of KEV Catalog vulnerabilities. Organizations with exploited vulnerabilities not yet in the catalog are encouraged to submit them for potential addition, provided they include CVE IDs, exploitation evidence, and mitigation guidance.
Facts Only
* CISA added two vulnerabilities to the Known Exploited Vulnerabilities (KEV) Catalog based on active exploitation evidence.
* The vulnerabilities are CVE-2026-102489 (Zammad GmbH Session Fixation Vulnerability).
* The vulnerabilities include CVE-2026-102490 (Zammad GmbH Improper Privilege Management Vulnerability).
* Binding Operational Directive (BOD) 26-04 establishes vulnerability management requirements for FCEB agencies.
* BOD 26-04 requires federal agencies to prioritize remediation of high-risk vulnerabilities listed in the KEV Catalog on publicly exposed assets that grant total post-exploitation control.
* BOD 26-04 requires agencies to defer action for lower-risk vulnerabilities while prioritizing those in the KEV Catalog.
* BOD 26-04 establishes expectations for checking if threat actors compromised a system prior to applying a patch.
* CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities.
* Organizations can submit exploited vulnerabilities for potential addition to the KEV Catalog via CISA’s nomination form, requiring CVE ID, exploitation evidence, and mitigation guidance.
Full Take
The structure surrounding this information highlights a tension between centralized risk classification (CISA's KEV Catalog) and decentralized organizational responsibility (BOD 26-04). The operational requirement demands specific action based on high-risk exposure, while the broader encouragement delegates the prioritization methodology to individual entities. This creates a potential gap where the enforcement of KEV prioritization might vary depending on an organization's internal risk calculus versus CISA's explicit mandate.
The act of adding vulnerabilities like those in the Zammad software into the public catalog serves as a mechanism for externalizing threat awareness, leveraging collective visibility to drive defensive action across disparate entities. The framework suggests that effective resilience relies not just on identifying known exploits, but on institutionalizing the process of risk-based assessment—determining which vulnerabilities are truly capable of granting "total control post-exploitation" within an organization's specific context, rather than relying solely on a blanket list.
The implication is that sovereignty over security becomes contextualized: while federal bodies set high-level directives, the actual decision-making about remediation must be grounded in local asset exposure and risk tolerance. The reliance on submitting external evidence for KEV addition introduces an accountability structure where the burden of proof rests on the organization to validate the exploitation claim, which shifts the dynamic from simple notification to active, verifiable intelligence contribution.
Bridge Questions: How can organizations effectively translate CISA’s high-level prioritization criteria into actionable, measurable remediation SLAs? What mechanisms can be established to ensure that the evidence submitted for KEV addition is consistently assessed and integrated by CISA without overwhelming their capacity? If vulnerability management success depends on localized risk assessment, how does this interact with centralized federal security directives?
From the original · US-CERT
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. - CVE-2026-102489 Zammad GmbH Zammad Session Fixation Vulnerability - CVE-2026-102490 Zammad GmbH Zammad Improper Privilege Management Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to…Read the full story at cisa.gov
Sentinel — Human
The text appears to be a factual summary of CISA policy regarding vulnerability tracking and remediation, exhibiting the structured language typical of official advisories rather than synthetic generation.
