senn-techsenn-tech
← IT News
Week 2026-W412026-10-03

IT News W41/2026: Zammad zero-days in the KEV, LiteLLM admin via salt key, Exchange Online blocks EWS

ZammadLiteLLMExchange OnlineNVIDIANISG

This edition covers Wednesday 30 September to Saturday 3 October. Monday and Tuesday are in the W40 edition. Six new posts appeared today, plus seven since Wednesday. Two of this week's stories hit software we run ourselves, Zammad and LiteLLM. We updated both on the evening of 3 October, and the versions are given below.

Deep dive: Zammad zero-days, from the DIVD breach to the KEV

The Dutch DIVD was attacked on 21 September through its own Zammad. The two flaws, CVE-2026-102489 (session fixation with code execution) and CVE-2026-102490 (privilege escalation to root), have been in CISA's KEV catalogue since 2 October. DIVD and the vendor disagree on the affected versions: DIVD says the faulty code is also in 7.0.0 to 7.1.3 but not exploitable there, Zammad considers 7.0 and later unaffected and hardened the code in 7.2.0 anyway. As of Saturday there is no confirmed fix for the privilege escalation.

Our ticket system ran 7.0.0-9 until Saturday evening and has run 7.2.0 since. Two of our own customisations had to be ported: an overridden Rails class for outgoing mail, and the nginx configuration, because 7.2 clears three proxy headers. Version table, timeline and attack chain: Zammad zero-days.

Assessment: A helpdesk is on the internet by definition. Anyone still on 6.x has an exploited RCE; anyone on 7.x should move to 7.2 and keep an eye on the privilege escalation.

Deep dive: LiteLLM, one key for two jobs

GHSA-7hp6-4w63-5g45 (CVSS 9.9) describes how the proxy uses the same salt key for stored secrets and for session tokens. An account with the internal_user role can have a forged admin token encrypted and replay it, after which the MCP stdio endpoint runs arbitrary commands. Fixed in 1.100.4, 1.101.3, 1.102.2 and 1.103.1. A second report, GHSA-g5ff-637f-6q2m, lets an internal_user_viewer read local files up to the master key, fixed from 1.95.0. Neither has a CVE.

Both of our gateways ran 1.89.4 without EXPERIMENTAL_UI_LOGIN, so the critical flaw did not apply to them, the file-read flaw did. Since Saturday evening both run 1.100.4. Our own patch for /v1/messages logging is gone, because upstream now contains the fix. Version ranges, and why jumping to exactly 1.95.0 would be wrong: LiteLLM salt key.

Assessment: Anyone running LiteLLM with user accounts belongs on one of the four fix lines. 1.95.0 alone closes the file access and at the same time opens the critical range in the default configuration.

Deep dive: Exchange Online switches off EWS

Since 1 October Microsoft has blocked Exchange Web Services in Exchange Online for tenants that have not maintained an application allow list, and the final end is 1 April 2027 (Microsoft Learn). Apple Mail and Calendar on the Mac still speak EWS, not Microsoft Graph. Which clients and integrations depend on it, and what EWSEnabled and the app ID list need to contain: EWS switch-off.

Assessment: For companies with Macs in the house this is the most urgent item of the week, because it raises no error. Mailboxes just stop syncing.


Digest: Other important news

Security

  • NVIDIA closes 114 driver and vGPU flaws: 78 high, 36 medium, Linux fixes 615.71.09, 610.57.04, 595.91.07 and 580.178.04. Our three GPU hosts run 610.57.04, read with nvidia-smi on 3 October.
  • n8n with 14 advisories in one day: among them an unauthenticated bypass of the Send-and-Wait approval and code execution through the Git node; fixed in 2.42.1, 2.41.4 and 1.123.83.
  • Next.js 16.3.8 and 15.5.27: SSRF in image optimisation (CVE-2026-94483, only with images.remotePatterns) and cache poisoning on self-hosted Pages Router pages (CVE-2026-94543). Our Next sites use neither remotePatterns nor the Pages Router.
  • FortiMail CVE-2026-104286: CVSS 9.8, exploited, no patch; the workaround is to switch off IBE.
  • Cisco Catalyst SD-WAN Manager CVE-2026-76504: login can be bypassed, exploited, in the KEV since 30 September.
  • NetScaler, new zero-day: since Friday evening an exploit has been circulating against fully patched appliances, with no CVE and no patch yet.
  • MCP Python SDK: a malicious MCP server can redirect OAuth secrets to its own token endpoint, fixed in 1.30.0 and 2.2.0.
  • vm2 3.11.7: 13 sandbox escapes at once, several with CVSS 10.0, all versions up to 3.11.6 affected.
  • Apache httpd 2.4.69: 19 CVEs, none rated higher than "moderate" by Apache.
  • Nginx Proxy Manager: still no version that fixes the two reports from 29 September, the latest release is 2.16.0.

Regulation

  • NISG 2026 in force: the Austrian NIS2 law has applied since 1 October, and the Federal Office for Cybersecurity started the same day. Registration through the USP application "NIS 2 Services" until 1 January 2027, reporting duties from day one. Our guide: NISG registration.

AI and development

Hardware

Software releases

From the blog

Six posts from Saturday:

Also since Wednesday:

Sources of this edition

Every address was reachable on 3 October 2026, and the evidence for the blog posts is given in each post. The version levels of our own systems (Zammad, LiteLLM, NVIDIA driver, Next.js) were read from the hosts on the same day.

Compiled on Saturday, 3 October 2026. What arrives on Sunday goes into the next edition.