On Friday CISA added two Zammad helpdesk flaws to the known-exploited catalog: CVE-2026-102489 and CVE-2026-102490. CISA says both are based on evidence of active exploitation and does not name a ransomware crew. Ransomware use is listed as unknown. Federal civilian agencies are due Monday, October 5. That date is in the catalog.

If that helpdesk is yours, DIVD’s instruction is upgrade to Zammad version 7 or take the instance offline. There is no workaround on DIVD’s page. Updating does not tell you whether someone already got in; DIVD published a log-check script on the case page for hunting. People who do not run Zammad have nothing to install. This is a helpdesk box, not a phone update.

A separate note for shops that run GitLab Duo’s self-hosted AI Gateway. On Friday GitLab shipped fixed builds 19.2.4, 19.3.2, and 19.4.1 for CVE-2026-90970. GitLab says GitLab-hosted AI Gateways are already covered. Customers on GitLab.com, GitLab Dedicated, and Self-Managed instances that use a GitLab-hosted gateway do not need to act. This is not a blanket patch for every GitLab CE or EE server. People who do not run a self-hosted AI Gateway have nothing to install.