{"schema_version":1,"title":"Zammad vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 41 vulnerabilities in Zammad: 30 in the last 7 days and 31 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-84465, was published on 25 September 2026.","url":"https://junglewise.ai/threats/technologies/zammad","json_url":"https://junglewise.ai/threats/technologies/zammad.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/zammad","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":2,"all_time":41,"critical":0,"exploited":0,"last_7_days":30,"last_30_days":30,"last_90_days":31,"last_365_days":41},"latest":[{"cve":"CVE-2026-84465","slug":"cve-2026-84465-zammad-is-a-web-based-open-source-helpdesk-customer-support","title":"Zammad S/MIME signature verification bypass allows sender impersonation","severity":"info","exploited":false,"published_at":"2026-09-25T19:17:58.123+00:00","url":"https://junglewise.ai/threats/cve-2026-84465-zammad-is-a-web-based-open-source-helpdesk-customer-support"},{"cve":"CVE-2026-84464","slug":"cve-2026-84464-zammad-is-a-web-based-open-source-helpdesk-customer-support","title":"Zammad unauthorized data access in External Data Source","severity":"info","exploited":false,"published_at":"2026-09-25T19:17:57.917+00:00","url":"https://junglewise.ai/threats/cve-2026-84464-zammad-is-a-web-based-open-source-helpdesk-customer-support"},{"cve":"CVE-2026-84463","slug":"cve-2026-84463-zammad-is-a-web-based-open-source-helpdesk-customer-support","title":"Zammad HTML injection in Knowledge Base video widget","severity":"info","exploited":false,"published_at":"2026-09-25T19:17:57.763+00:00","url":"https://junglewise.ai/threats/cve-2026-84463-zammad-is-a-web-based-open-source-helpdesk-customer-support"},{"cve":"CVE-2026-84461","slug":"cve-2026-84461-zammad-is-a-web-based-open-source-helpdesk-customer-support","title":"Zammad missing rate limiting in two-factor login","severity":"info","exploited":false,"published_at":"2026-09-25T19:17:57.467+00:00","url":"https://junglewise.ai/threats/cve-2026-84461-zammad-is-a-web-based-open-source-helpdesk-customer-support"},{"cve":"CVE-2026-84460","slug":"cve-2026-84460-zammad-is-a-web-based-open-source-helpdesk-customer-support","title":"Zammad information disclosure via tag enumeration","severity":"info","exploited":false,"published_at":"2026-09-25T19:17:57.307+00:00","url":"https://junglewise.ai/threats/cve-2026-84460-zammad-is-a-web-based-open-source-helpdesk-customer-support"},{"cve":"CVE-2026-84458","slug":"cve-2026-84458-zammad-is-a-web-based-open-source-helpdesk-customer-support","title":"Zammad account takeover via unverified email matching in SSO auto-link","severity":"info","exploited":false,"published_at":"2026-09-25T19:17:57.13+00:00","url":"https://junglewise.ai/threats/cve-2026-84458-zammad-is-a-web-based-open-source-helpdesk-customer-support"},{"cve":"CVE-2026-63216","slug":"cve-2026-63216-zammad-is-a-web-based-open-source-helpdesk-customer-support","title":"Zammad stored XSS in option labels configuration dialog","severity":"info","exploited":false,"published_at":"2026-09-25T19:17:55.517+00:00","url":"https://junglewise.ai/threats/cve-2026-63216-zammad-is-a-web-based-open-source-helpdesk-customer-support"},{"cve":"CVE-2026-63208","slug":"cve-2026-63208-zammad-is-a-web-based-open-source-helpdesk-customer-support","title":"Zammad OAuth token exposure in Microsoft Graph error logs","severity":"info","exploited":false,"published_at":"2026-09-25T19:17:55.347+00:00","url":"https://junglewise.ai/threats/cve-2026-63208-zammad-is-a-web-based-open-source-helpdesk-customer-support"},{"cve":"CVE-2026-63207","slug":"cve-2026-63207-zammad-is-a-web-based-open-source-helpdesk-customer-support","title":"Zammad sensitive information exposure in integration API","severity":"info","exploited":false,"published_at":"2026-09-25T19:17:55.16+00:00","url":"https://junglewise.ai/threats/cve-2026-63207-zammad-is-a-web-based-open-source-helpdesk-customer-support"},{"cve":"CVE-2026-63206","slug":"cve-2026-63206-zammad-is-a-web-based-open-source-helpdesk-customer-support","title":"Zammad HTML sanitizer bypass via shortened URL scheme","severity":"info","exploited":false,"published_at":"2026-09-25T19:17:54.993+00:00","url":"https://junglewise.ai/threats/cve-2026-63206-zammad-is-a-web-based-open-source-helpdesk-customer-support"},{"cve":"CVE-2026-63205","slug":"cve-2026-63205-zammad-is-a-web-based-open-source-helpdesk-customer-support","title":"Zammad authorization bypass via email signature attachments","severity":"info","exploited":false,"published_at":"2026-09-25T19:17:54.837+00:00","url":"https://junglewise.ai/threats/cve-2026-63205-zammad-is-a-web-based-open-source-helpdesk-customer-support"},{"cve":"CVE-2026-63204","slug":"cve-2026-63204-zammad-is-a-web-based-open-source-helpdesk-customer-support","title":"Zammad information disclosure in AI ticket summarize endpoint","severity":"info","exploited":false,"published_at":"2026-09-25T19:17:54.667+00:00","url":"https://junglewise.ai/threats/cve-2026-63204-zammad-is-a-web-based-open-source-helpdesk-customer-support"},{"cve":"CVE-2026-63006","slug":"cve-2026-63006-zammad-is-a-web-based-open-source-helpdesk-customer-support","title":"Zammad HTML sanitizer path traversal in image URLs","severity":"info","exploited":false,"published_at":"2026-09-25T19:17:54.5+00:00","url":"https://junglewise.ai/threats/cve-2026-63006-zammad-is-a-web-based-open-source-helpdesk-customer-support"},{"cve":"CVE-2026-61855","slug":"cve-2026-61855-zammad-is-a-web-based-open-source-helpdesk-customer-support","title":"Zammad invalid PGP signature verification on inbound email","severity":"info","exploited":false,"published_at":"2026-09-25T19:17:53.963+00:00","url":"https://junglewise.ai/threats/cve-2026-61855-zammad-is-a-web-based-open-source-helpdesk-customer-support"},{"cve":"CVE-2026-84462","slug":"cve-2026-84462-zammad-is-a-web-based-open-source-helpdesk-customer-support","title":"Zammad AI Agent template sanitizer bypass in ERB configuration","severity":"info","exploited":false,"published_at":"2026-09-25T18:17:30.797+00:00","url":"https://junglewise.ai/threats/cve-2026-84462-zammad-is-a-web-based-open-source-helpdesk-customer-support"},{"cve":"CVE-2026-65828","slug":"cve-2026-65828-zammad-is-a-web-based-open-source-helpdesk-customer-support","title":"Zammad attachment upload deletion bypass in legacy endpoint","severity":"info","exploited":false,"published_at":"2026-09-25T18:17:29.193+00:00","url":"https://junglewise.ai/threats/cve-2026-65828-zammad-is-a-web-based-open-source-helpdesk-customer-support"},{"cve":"CVE-2026-61525","slug":"cve-2026-61525-zammad-is-a-web-based-open-source-helpdesk-customer-support","title":"Zammad path traversal in session management","severity":"info","exploited":false,"published_at":"2026-09-25T18:17:29.03+00:00","url":"https://junglewise.ai/threats/cve-2026-61525-zammad-is-a-web-based-open-source-helpdesk-customer-support"},{"cve":"CVE-2026-56735","slug":"cve-2026-56735-zammad-is-a-web-based-open-source-helpdesk-customer-support","title":"Zammad HTML sanitizer bypass via srcset attribute","severity":"info","exploited":false,"published_at":"2026-09-25T18:17:28.88+00:00","url":"https://junglewise.ai/threats/cve-2026-56735-zammad-is-a-web-based-open-source-helpdesk-customer-support"},{"cve":"CVE-2026-56734","slug":"cve-2026-56734-zammad-is-a-web-based-open-source-helpdesk-customer-support","title":"Zammad SSRF in federated authentication profile image fetch","severity":"info","exploited":false,"published_at":"2026-09-25T18:17:27.7+00:00","url":"https://junglewise.ai/threats/cve-2026-56734-zammad-is-a-web-based-open-source-helpdesk-customer-support"},{"cve":"CVE-2026-56733","slug":"cve-2026-56733-zammad-is-a-web-based-open-source-helpdesk-customer-support","title":"Zammad authorization bypass in token-based access control","severity":"info","exploited":false,"published_at":"2026-09-25T18:17:27.533+00:00","url":"https://junglewise.ai/threats/cve-2026-56733-zammad-is-a-web-based-open-source-helpdesk-customer-support"},{"cve":"CVE-2026-56732","slug":"cve-2026-56732-zammad-is-a-web-based-open-source-helpdesk-customer-support","title":"Zammad HTML sanitization session termination","severity":"info","exploited":false,"published_at":"2026-09-25T18:17:27.37+00:00","url":"https://junglewise.ai/threats/cve-2026-56732-zammad-is-a-web-based-open-source-helpdesk-customer-support"},{"cve":"CVE-2026-56731","slug":"cve-2026-56731-zammad-is-a-web-based-open-source-helpdesk-customer-support","title":"Zammad cross-site scripting in ticket creation","severity":"info","exploited":false,"published_at":"2026-09-25T18:17:27.213+00:00","url":"https://junglewise.ai/threats/cve-2026-56731-zammad-is-a-web-based-open-source-helpdesk-customer-support"},{"cve":"CVE-2026-56730","slug":"cve-2026-56730-zammad-is-a-web-based-open-source-helpdesk-customer-support","title":"Zammad authorization bypass in knowledge base answer GraphQL mutation","severity":"info","exploited":false,"published_at":"2026-09-25T18:17:27.063+00:00","url":"https://junglewise.ai/threats/cve-2026-56730-zammad-is-a-web-based-open-source-helpdesk-customer-support"},{"cve":"CVE-2026-56728","slug":"cve-2026-56728-zammad-is-a-web-based-open-source-helpdesk-customer-support","title":"Zammad broken access control in GraphQL API taskbar","severity":"info","exploited":false,"published_at":"2026-09-25T18:17:26.797+00:00","url":"https://junglewise.ai/threats/cve-2026-56728-zammad-is-a-web-based-open-source-helpdesk-customer-support"},{"cve":"CVE-2026-56727","slug":"cve-2026-56727-zammad-is-a-web-based-open-source-helpdesk-customer-support","title":"Zammad PGP signature verification bypass in email processing","severity":"info","exploited":false,"published_at":"2026-09-25T18:17:26.63+00:00","url":"https://junglewise.ai/threats/cve-2026-56727-zammad-is-a-web-based-open-source-helpdesk-customer-support"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":30}],"related":[],"technology":{"hub":true,"name":"Zammad","slug":"zammad","vendor":{"name":"Zammad","slug":"zammad","url":"https://junglewise.ai/threats/vendors/zammad"},"aliases":[],"category":"web-application","homepage":"https://zammad.org/","repo_url":"https://github.com/zammad/zammad","description":"Zammad is an open-source helpdesk and customer support platform with a web-based interface.","url":"https://junglewise.ai/threats/technologies/zammad"},"most_severe":[{"cve":"CVE-2026-34723","cvss":7.5,"epss":0.0044,"slug":"cve-2026-34723-zammad-improper-access-control-in-getting-started-controller","title":"Zammad improper access control in getting_started_controller","severity":"high","exploited":false,"published_at":"2026-04-08T19:25:22.58+00:00","url":"https://junglewise.ai/threats/cve-2026-34723-zammad-improper-access-control-in-getting-started-controller"},{"cve":"CVE-2026-34724","cvss":7.2,"epss":0.0026,"slug":"cve-2026-34724-zammad-server-side-template-injection-in-ai-agent","title":"Zammad server-side template injection in AI Agent","severity":"high","exploited":false,"published_at":"2026-04-08T19:25:22.723+00:00","url":"https://junglewise.ai/threats/cve-2026-34724-zammad-server-side-template-injection-in-ai-agent"},{"cve":"CVE-2026-34721","cvss":6.5,"epss":0.001,"slug":"cve-2026-34721-zammad-csrf-in-oauth-callback-endpoints","title":"Zammad CSRF in OAuth callback endpoints","severity":"medium","exploited":false,"published_at":"2026-04-08T19:25:22.29+00:00","url":"https://junglewise.ai/threats/cve-2026-34721-zammad-csrf-in-oauth-callback-endpoints"},{"cve":"CVE-2026-34718","cvss":6.1,"epss":0.0015,"slug":"cve-2026-34718-zammad-html-sanitizer-xss-in-ticket-articles","title":"Zammad HTML sanitizer XSS in ticket articles","severity":"medium","exploited":false,"published_at":"2026-04-08T19:25:21.863+00:00","url":"https://junglewise.ai/threats/cve-2026-34718-zammad-html-sanitizer-xss-in-ticket-articles"},{"cve":"CVE-2026-34248","cvss":5.7,"epss":0.0019,"slug":"cve-2026-34248-zammad-improper-access-control-in-ticket-detail-view","title":"Zammad improper access control in ticket detail view","severity":"medium","exploited":false,"published_at":"2026-04-08T19:25:21.567+00:00","url":"https://junglewise.ai/threats/cve-2026-34248-zammad-improper-access-control-in-ticket-detail-view"},{"cve":"CVE-2026-34719","cvss":4.3,"epss":0.0024,"slug":"cve-2026-34719-zammad-ssrf-in-webhook-model","title":"Zammad SSRF in webhook model","severity":"medium","exploited":false,"published_at":"2026-04-08T19:25:22.003+00:00","url":"https://junglewise.ai/threats/cve-2026-34719-zammad-ssrf-in-webhook-model"},{"cve":"CVE-2026-34837","cvss":4.3,"epss":0.0018,"slug":"cve-2026-34837-zammad-missing-authorization-in-ai-assistance-text-tools","title":"Zammad missing authorization in AI assistance text tools","severity":"medium","exploited":false,"published_at":"2026-04-08T19:25:23.007+00:00","url":"https://junglewise.ai/threats/cve-2026-34837-zammad-missing-authorization-in-ai-assistance-text-tools"},{"cve":"CVE-2026-34782","cvss":4.3,"epss":0.0017,"slug":"cve-2026-34782-zammad-missing-authorization-in-ai-assistance-text-tools","title":"Zammad missing authorization in AI assistance text tools","severity":"medium","exploited":false,"published_at":"2026-04-08T19:25:22.867+00:00","url":"https://junglewise.ai/threats/cve-2026-34782-zammad-missing-authorization-in-ai-assistance-text-tools"},{"cve":"CVE-2026-34722","cvss":4.3,"epss":0.0017,"slug":"cve-2026-34722-zammad-missing-authorization-in-ticket-creation-endpoint","title":"Zammad missing authorization in ticket creation endpoint","severity":"medium","exploited":false,"published_at":"2026-04-08T19:25:22.44+00:00","url":"https://junglewise.ai/threats/cve-2026-34722-zammad-missing-authorization-in-ticket-creation-endpoint"},{"cve":"CVE-2026-34720","cvss":4.3,"epss":0.001,"slug":"cve-2026-34720-zammad-origin-validation-error-in-sso-mechanism","title":"Zammad origin validation error in SSO mechanism","severity":"medium","exploited":false,"published_at":"2026-04-08T19:25:22.15+00:00","url":"https://junglewise.ai/threats/cve-2026-34720-zammad-origin-validation-error-in-sso-mechanism"}],"generated_at":"2026-09-26T11:07:00.153785+00:00"}