Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability Disclosure
Attackers exploited two Zammad zero-days to breach DIVD, reach root, and steal volunteer contact data.
The Dutch Institute for Vulnerability Disclosure said attackers exploited two Zammad zero-days after suspicious activity was noticed on September 24. Remote code execution flaw CVE-2026-102489 and elevation-of-privilege flaw CVE-2026-102490, scored 9.4 CVSS when chained, were used to hijack sessions, run code, and escalate from the Zammad user to root within seconds. Attackers then reached other services and exfiltrated data, including volunteer email addresses and possibly contact details. DIVD said script notes in the logs indicate an agentic AI-driven attack and urged every Zammad deployment to update to version 7 or be taken offline.