Zammad

Zammad GmbH · current 7.2.2

Are you Zammad GmbH? Claim this page

The current version of Zammad is 7.2.2 (as of 09/10/2026). patchletter checks the official source daily and emails you new releases.

Actively exploited vulnerabilities

The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. What CISA does not carry does not appear in this list — even where it is being exploited.

  • CVE-2026-102489Zammad GmbH Zammad Session Fixation Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 5 Oct

  • CVE-2026-102490Zammad GmbH Zammad Improper Privilege Management Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 5 Oct

Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.

BSI security advisories

Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.

All BSI advisories →

Zammad at a glance

Zammad is a popular open-source helpdesk and ticketing system, common in SMBs and support teams, especially in Europe. Zammad ships regular releases plus security fixes; as a web application holding customer communications and often integrated with mail, hardening and timely updates matter.

For admins updates run through the documented procedure (package or Docker) and include database migrations — back up the database and attachments first, and mind the required Elasticsearch and database versions. Zammad has had security advisories, so apply security releases promptly. Keep it off the open internet behind authentication and TLS, and secure the mail and API integrations it uses. After upgrading, verify login, ticketing, search and mail flow. The many channels (email, chat, integrations) widen the input surface — keep them configured deliberately. Track the version and its support window; patchletter surfaces new Zammad releases so security fixes aren't missed.

Version history & changelog · as detected by patchletter

VersionChannelDateNotes
7.2.2STABLE09/10/2026Release notes →
7.2.1STABLE06/10/2026Release notes →
7.2.0STABLE23/09/2026Release notes →
7.1.3STABLE26/08/2026Release notes →
7.1.2STABLE05/08/2026Release notes →
7.1.1STABLE08/07/2026Release notes →

Frequently asked questions

What is the latest version of Zammad?
Zammad 7.2.2, released 09/10/2026. patchletter checks the vendor's official source daily for new releases.
Where can I find the Zammad release notes?
The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
How do I get notified about new Zammad updates?
Tick Zammad off in the catalogue and leave your address. From then on new versions go out by email — one at a time, or bundled in the daily or weekly digest.

An email as soon as a new Zammad version ships

We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The update email is free and ends with one click. Alerts about vulnerabilities and end of support are part of patchletter Pro.

Embed this badge

The badge shows the current Zammad version and keeps it up to date. Anyone may embed it, no account needed.

Zammad badge
[![Zammad](https://patchletter.com/badge/zammad.svg)](https://patchletter.com/en/software/zammad)
https://patchletter.com/badge/zammad.svg

Also available: ?v=eol (end of support) and ?v=cve (actively exploited).

Related tools in Monitoring & ITSM