DIVD says Zammad zero-days enabled AI-driven network breach
An autonomous AI agent used two Zammad zero-days to breach DIVD, gain root, and exfiltrate data within seconds.
The Dutch Institute for Vulnerability Disclosure says its network was breached by an autonomous AI agent that chained two zero-days in the Zammad helpdesk, CVE-2026-102489 and CVE-2026-102490. The flaws allowed session hijacking, remote code execution, and escalation from the Zammad user to root, after which the attacker reached other services and exfiltrated data within seconds. Segmentation and incident response limited deeper movement, and the investigation is ongoing. Working with Merlon Security, DIVD urges customers to upgrade to Zammad 7 or take vulnerable instances offline; Zammad cites more than 2,000 customers and 55,000 users.
- Two Zammad zero-days enabled session hijacking, remote code execution, and root.
- An autonomous AI agent exfiltrated DIVD data within seconds of exploitation.
- Segmentation and response stopped deeper movement; the investigation continues.
- Users should upgrade to Zammad 7 or take instances offline.
Vulnerabilities mentionedAll →
- CVE-2026-1024899.4—Session hijack to RCE in Zammadpublished · Zammad+1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
CVE-2026-102489+1 related CVE | Session hijack to RCE in Zammad Zammad, an open-source helpdesk, has a session-hijacking flaw that can be turned into remote code execution as the zammad operating-system user. It is reachable over the network with no prior privileges; CVSS 4.0 rates it 9.4 critical, with passive user interaction, automatable exploitation, and high impact on the application and on subsequent systems. Versions 6.3.0 through 6.5.4 are exploitable. The same flaw is present in 7.0.0 through 7.1.3 but is not exploitable under the environment conditions described in the advisory. CVSS exploit maturity is Attacked (E:A), so exploitation is treated as reported, although the issue is not in CISA KEV and no public proof-of-concept is known. |
Full article363 words · extracted from bleepingcomputer.com · click to collapse

The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system.
Previously, the nonprofit organization of volunteer security researchers said the attack was “loud and very, very messy,” driven by an AI agent that moved autonomously and decided its next steps without external intervention or direction.
DIVD retrieved extensive details about the attack because the AI agent left behind clear explanations of its decisions, allowing the organization to reconstruct the incident.
According to the cybersecurity nonprofit, the two flaws, now identified as CVE-2026-102489 and CVE-2026-102490, enabled session hijacking, remote code execution, and escalation to root privileges.
After exploiting the vulnerabilities, the attacker was able to access other services, read and exfiltrate data from DIVD's systems, all actions performed in a matter of seconds, thanks to AI automation.
“Used together, they allowed the attackers to hijack sessions, run code remotely, and escalate privileges from the Zammad user to root, in seconds, due to the agentic part of this hack,” DIVD says.
Due to network segmentation and incident response actions, the threat actor did not move deeper into the network. However, the investigation is still underway.
Zammad is an open-source AI-powered helpdesk and support ticketing platform used to manage customer inquiries, IT support requests, and internal ticketing.
The solution is available as a self-hosted or hosted service, and Zammad claims on its website that it has over 2,000 customers and 55,000 users, including De’Longhi, Amnesty International, and NextCloud.
DIVD discovered the zero-day vulnerabilities in collaboration with Merlon Security. The organization notified Zammad about the issue and is alerting other users of vulnerable instances.
The nonprofit recommends that Zammad users upgrade to version 7, which is considered safe, or take the instance offline as soon as possible.
DIVD has promised to share additional updates about the incident tomorrow.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.