Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

zammad

About This Vendor

zammad is a technology vendor producing software and infrastructure products. As a software provider, zammad's broad product portfolio across multiple domains—including operating systems, cloud infrastructure, enterprise applications, databases, networking, and security tools—creates a large attack surface. Additionally, long support cycles, widespread deployment, and continuous feature development contribute to the accumulation of discovered vulnerabilities over time. Major vendors typically report higher CVE counts not necessarily due to inferior security, but because of greater exposure to security research, responsible disclosure practices, and the sheer complexity of maintaining multiple product lines and legacy systems. Regular security assessments and patching of zammad's products are critical for organizations running their software in production environments.

Vulnerability Trends for This Vendor

SecUtils has indexed 90 known vulnerabilities from zammad. This includes 10 critical-severity issues and 18 high-severity issues that represent significant risk. These vulnerabilities affect 1 distinct product across zammad's portfolio, demonstrating the breadth of the vendor's product ecosystem and the importance of comprehensive patch management strategies. Disclosure dates span from 2017 through 2026, reflecting sustained security scrutiny over multiple years. Organizations deploying zammad products should maintain active vulnerability monitoring, prioritize critical patches, and implement compensating controls where patches cannot be applied immediately.

ID Date Published Last Modified Severity (CVSSv3) Severity (CVSSv2) Exploit Available
CVE-2017-5619 2017-03-13 2026-05-13 9.8 7.5 Likely
CVE-2017-5620 2017-03-13 2026-05-13 6.1 4.3 Likely
CVE-2017-5621 2017-03-13 2026-05-13 6.1 4.3 Likely
CVE-2017-6080 2017-03-13 2026-05-13 9.8 7.5 Likely
CVE-2017-6081 2017-03-13 2026-05-13 8.8 6.8 Likely
CVE-2018-1000154 2018-04-05 2024-11-21 6.1 4.3 Likely
CVE-2019-1010018 2019-07-16 2024-11-21 6.1 4.3 Likely
CVE-2020-10096 2020-03-05 2024-11-21 7.5 5.0 Likely
CVE-2020-10097 2020-03-05 2024-11-21 5.3 5.0 Likely
CVE-2020-10098 2020-03-05 2024-11-21 5.4 3.5 Unknown
CVE-2020-10099 2020-03-05 2024-11-21 5.4 3.5 Unknown
CVE-2020-10100 2020-03-05 2024-11-21 6.5 4.0 Likely
CVE-2020-10101 2020-03-05 2024-11-21 7.5 5.0 Likely
CVE-2020-10102 2020-03-05 2024-11-21 5.3 3.5 Unknown
CVE-2020-10103 2020-03-05 2024-11-21 5.4 3.5 Unknown
CVE-2020-10104 2020-03-05 2024-11-21 4.3 4.0 Likely
CVE-2020-10105 2020-03-05 2024-11-21 5.3 5.0 Likely
CVE-2020-14213 2020-06-16 2024-11-21 5.4 5.5 Likely
CVE-2020-14214 2020-06-16 2024-11-21 6.5 5.8 Likely
CVE-2020-26028 2020-12-28 2024-11-21 4.9 4.0 Likely
CVE-2020-26029 2020-12-28 2024-11-21 6.5 4.0 Likely
CVE-2020-26030 2020-12-28 2024-11-21 9.8 7.5 Likely
CVE-2020-26031 2020-12-28 2024-11-21 4.3 4.0 Likely
CVE-2020-26032 2020-12-28 2024-11-21 7.5 5.0 Likely
CVE-2020-26033 2020-12-28 2024-11-21 5.4 5.8 Likely
CVE-2020-26034 2020-12-28 2024-11-21 4.3 4.0 Likely
CVE-2020-26035 2020-12-28 2024-11-21 5.4 3.5 Unknown
CVE-2020-29158 2020-12-28 2024-11-21 4.3 4.0 Likely
CVE-2020-29159 2020-12-28 2024-11-21 4.9 4.0 Likely
CVE-2020-29160 2020-12-28 2024-11-21 7.5 5.0 Likely
CVE-2021-35298 2021-06-28 2024-11-21 6.1 4.3 Likely
CVE-2021-35299 2021-06-28 2024-11-21 7.5 5.0 Likely
CVE-2021-35300 2021-06-28 2024-11-21 4.3 4.3 Likely
CVE-2021-35301 2021-06-28 2024-11-21 5.3 5.0 Likely
CVE-2021-35302 2021-06-28 2024-11-21 5.3 5.0 Likely
CVE-2021-35303 2021-06-28 2024-11-21 6.1 4.3 Likely
CVE-2021-42092 2021-10-07 2024-11-21 5.4 3.5 Unknown
CVE-2021-42093 2021-10-07 2024-11-21 7.2 6.5 Likely
CVE-2021-42094 2021-10-07 2024-11-21 9.8 7.5 Likely
CVE-2021-42084 2021-10-07 2024-11-21 6.5 4.0 Likely
CVE-2021-42085 2021-10-07 2024-11-21 5.4 3.5 Unknown
CVE-2021-42086 2021-10-07 2024-11-21 8.8 6.5 Likely
CVE-2021-42087 2021-10-07 2024-11-21 4.9 4.0 Likely
CVE-2021-42088 2021-10-07 2024-11-21 6.1 4.3 Likely
CVE-2021-42089 2021-10-07 2024-11-21 7.5 5.0 Likely
CVE-2021-42090 2021-10-07 2024-11-21 9.8 7.5 Likely
CVE-2021-42091 2021-10-07 2024-11-21 9.1 6.4 Likely
CVE-2021-42137 2021-10-11 2024-11-21 5.3 5.0 Likely
CVE-2021-43145 2022-02-04 2024-11-21 8.1 5.5 Likely
CVE-2021-44886 2022-02-04 2024-11-21 5.3 5.0 Likely
CVE-2022-27331 2022-04-27 2024-11-21 4.3 4.0 Likely
CVE-2022-27332 2022-04-27 2024-11-21 9.1 5.8 Likely
CVE-2022-29700 2022-04-27 2024-11-21 7.5 5.0 Likely
CVE-2022-29701 2022-04-27 2024-11-21 7.5 5.0 Likely
CVE-2022-35487 2022-08-08 2024-11-21 7.5 - -
CVE-2022-35488 2022-08-08 2024-11-21 7.5 - -
CVE-2022-35489 2022-08-08 2024-11-21 6.5 - -
CVE-2022-35490 2022-08-08 2024-11-21 9.8 - -
CVE-2022-40816 2022-09-27 2025-05-21 6.5 - -
CVE-2022-40817 2022-09-27 2025-05-21 4.3 - -
CVE-2022-48021 2023-02-03 2025-03-26 9.8 - -
CVE-2022-48022 2023-02-03 2025-03-26 4.3 - -
CVE-2022-48023 2023-02-03 2024-11-21 4.3 - -
CVE-2023-29867 2023-05-02 2025-01-30 6.5 - -
CVE-2023-29868 2023-05-02 2025-01-30 6.5 - -
CVE-2023-31597 2023-05-18 2025-01-22 6.5 - -
CVE-2023-50453 2023-12-10 2024-11-21 5.3 - -
CVE-2023-50454 2023-12-10 2024-11-21 5.9 - -
CVE-2023-50455 2023-12-10 2024-11-21 7.5 - -
CVE-2023-50456 2023-12-10 2025-05-27 5.3 - -
CVE-2023-50457 2023-12-10 2024-11-21 4.3 - -
CVE-2024-33666 2024-04-26 2025-04-15 8.6 - -
CVE-2024-33667 2024-04-26 2025-04-15 6.5 - -
CVE-2024-33668 2024-04-26 2025-04-15 9.1 - -
CVE-2024-36078 2024-05-19 2025-04-15 6.7 - -
CVE-2024-55578 2024-12-09 2025-04-15 4.3 - -
CVE-2025-32357 2025-04-05 2025-04-15 4.3 - -
CVE-2025-32358 2025-04-05 2025-04-15 4.0 - -
CVE-2025-32359 2025-04-05 2025-04-15 4.8 - -
CVE-2025-32360 2025-04-05 2025-04-15 4.2 - -
CVE-2026-34248 2026-04-08 2026-04-17 5.7 - -
CVE-2026-34718 2026-04-08 2026-04-17 6.1 - -
CVE-2026-34719 2026-04-08 2026-04-17 4.3 - -
CVE-2026-34720 2026-04-08 2026-04-17 4.3 - -
CVE-2026-34721 2026-04-08 2026-04-17 6.5 - -
CVE-2026-34722 2026-04-08 2026-04-17 4.3 - -
CVE-2026-34723 2026-04-08 2026-04-17 7.5 - -
CVE-2026-34724 2026-04-08 2026-04-17 7.2 - -
CVE-2026-34782 2026-04-08 2026-04-17 4.3 - -
CVE-2026-34837 2026-04-08 2026-04-17 4.3 - -

How SecUtils Normalizes Vendor Data

SecUtils aggregates National Vulnerability Database (NVD) and MITRE records for zammad by normalizing vendor identifiers across diverse data sources, mapping vendor names to their associated product lines, and collecting all known vulnerabilities under a unified vendor context. For every CVE associated with zammad's products, we extract and structure Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) categories, CVSS severity metrics, and reference links to enable rapid vulnerability identification and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and vendor vulnerability tracking.