Security vulnerabilities I have responsibly disclosed. All findings were reported to the affected vendors and patched before public disclosure.

CVE / IDProductSummarySeverityDateReferences
CVE-2026-34724Zammadserver-side template injection to RCE via the new AI Agent featureHigh (8.7)2026-06-03CVE, GHSA, Blog post
CVE-2026-34719Zammaddirect-request server-side request forgery (SSRF) via webhooksHigh (8.3)2026-06-03CVE, GHSA, Blog post
CVE-2026-34718Zammadstored XSS / phishing via data: URI HTML sanitizer bypassModerate (5.3)2026-06-03CVE, GHSA, Blog post