Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY49 SECURITY RECORDS

Zammad GmbH

Zammad

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-102490 30 Sep 2026 Zammad: 1.5.0 < 7.1.0-alpha, * < 1.5.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-102489 30 Sep 2026 Zammad: * < 6.3.0, 6.3.0 < 6.5.4 Zammad: 7.0.0 < * Update reference ↗
CVE-2026-63208 25 Sep 2026 zammad: < 7.1.2 7.1.2. Update reference ↗
CVE-2026-63006 25 Sep 2026 zammad: < 7.1.2 7.1.2. Update reference ↗
CVE-2026-63204 25 Sep 2026 zammad: < 7.1.2 7.1.2. Update reference ↗
CVE-2026-61855 25 Sep 2026 zammad: < 7.1.2 7.1.2. Update reference ↗
CVE-2026-84461 25 Sep 2026 zammad: < 7.1.2 7.1.2. Update reference ↗
CVE-2026-63207 25 Sep 2026 zammad: < 7.1.2 7.1.2. Update reference ↗
CVE-2026-84465 25 Sep 2026 zammad: < 7.1.2 7.1.2. Update reference ↗
CVE-2026-84463 25 Sep 2026 zammad: < 7.1.2 7.1.2. Update reference ↗
CVE-2026-84464 25 Sep 2026 zammad: < 7.1.2 7.1.2. Update reference ↗
CVE-2026-63216 25 Sep 2026 zammad: < 7.1.2 7.1.2. Update reference ↗
CVE-2026-84458 25 Sep 2026 zammad: < 7.1.2 7.1.2. Update reference ↗
CVE-2026-84460 25 Sep 2026 zammad: < 7.1.2 7.1.2. Update reference ↗
CVE-2026-63206 25 Sep 2026 zammad: < 7.1.2 7.1.2. Update reference ↗
CVE-2026-63205 25 Sep 2026 zammad: < 7.1.2 7.1.2. Update reference ↗
CVE-2026-84462 25 Sep 2026 zammad: < 7.1.2 7.1.2. Update reference ↗
CVE-2026-65828 25 Sep 2026 zammad: < 7.1.2 7.1.2. Update reference ↗
CVE-2026-61525 25 Sep 2026 zammad: = 7.0.2, = 7.1.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-56728 25 Sep 2026 zammad: < 7.0.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-56725 25 Sep 2026 zammad: < 7.0.2 7.0.2. Update reference ↗
CVE-2026-56732 25 Sep 2026 zammad: < 7.0.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-56730 25 Sep 2026 zammad: < 7.0.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-56733 25 Sep 2026 zammad: < 7.0.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-56731 25 Sep 2026 zammad: < 7.0.1 7.0.1. Update reference ↗
CVE-2026-56735 25 Sep 2026 zammad: < 7.0.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-56727 25 Sep 2026 zammad: < 7.0.2 7.0.2. Update reference ↗
CVE-2026-56734 25 Sep 2026 zammad: < 7.0.2 7.0.2. Update reference ↗
CVE-2026-56726 25 Sep 2026 zammad: < 7.0.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-56729 25 Sep 2026 zammad: < 7.0.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-56723 25 Sep 2026 zammad: < 7.0.2 7.0.2. Update reference ↗
CVE-2026-56724 25 Sep 2026 zammad: < 7.0.2 7.0.2. Update reference ↗
CVE-2026-13229 4 Aug 2026 ≤ 7.0.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-34837 8 Apr 2026 >= 7.0.0, < 7.0.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-34782 8 Apr 2026 >= 7.0.0, < 7.0.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-34724 8 Apr 2026 >= 7.0.0, < 7.0.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-34723 8 Apr 2026 < 6.5.4; >= 7.0.0-alpha, < 7.0.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-34722 8 Apr 2026 < 6.5.4; >= 7.0.0-alpha, < 7.0.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-34721 8 Apr 2026 < 6.5.4; >= 7.0.0-alpha, < 7.0.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-34720 8 Apr 2026 < 6.5.4; >= 7.0.0-alpha, < 7.0.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-34719 8 Apr 2026 < 6.5.4; >= 7.0.0-alpha, < 7.0.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-34718 8 Apr 2026 < 6.5.4; >= 7.0.0-alpha, < 7.0.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-34248 8 Apr 2026 >= 7.0.0, < 7.0.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-32360 5 Apr 2025 6.4 < 6.4.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-32359 5 Apr 2025 6.4 < 6.4.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-32358 5 Apr 2025 6.4 < 6.4.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-32357 5 Apr 2025 6.4 < 6.4.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-33668 26 Apr 2024 zammad: 6.2.0 < 6.3.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2019-1010018 16 Jul 2019 ≤ 2.3.0 [fixed: 2.3.1; 2.2.2 and 2.1.3] An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.