Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability Disclosure
Attackers exploited two Zammad zero-days to breach DIVD, reach root, and steal volunteer contact data.
The Dutch Institute for Vulnerability Disclosure said attackers exploited two Zammad zero-days after suspicious activity was noticed on September 24. Remote code execution flaw CVE-2026-102489 and elevation-of-privilege flaw CVE-2026-102490, scored 9.4 CVSS when chained, were used to hijack sessions, run code, and escalate from the Zammad user to root within seconds. Attackers then reached other services and exfiltrated data, including volunteer email addresses and possibly contact details. DIVD said script notes in the logs indicate an agentic AI-driven attack and urged every Zammad deployment to update to version 7 or be taken offline.
- CVE-2026-102489 and CVE-2026-102490 were chained for remote code execution and root access.
- DIVD saw suspicious activity on September 24 and limited spread with network segmentation.
- Volunteer email addresses and possibly contact details were read and exfiltrated.
- DIVD says attacker logs show an AI agent justifying its actions.
- All Zammad users are urged to update to version 7 or take it offline.
Vulnerabilities mentionedAll →
- CVE-2026-1024899.4<1%Session hijack to RCE in Zammadpublished · Zammad KEV+1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
CVE-2026-102489+1 related CVE |
Full article515 words · extracted from infosecurity-magazine.com · click to collapse
A Dutch cybersecurity non-profit has revealed how it was compromised in an agentic AI attack that exploited two zero-day flaws in its helpdesk platform.
The Dutch Institute for Vulnerability Disclosure (DIVD) is staffed by volunteers and dedicated to ethically disclosing flaws it finds in systems to “make the digital world safer.”
However, it became a target itself last week after noticing suspicious activity on September 24.
In a LinkedIn post on September 30, the organization revealed that its attackers exploited two zero-days in Zammad.
“Used together, they allowed the attackers to hijack sessions, run code remotely and escalate privileges from the Zammad user to root, in seconds, due to the agentic part of this hack,” it said. “From there they were able to access other services and read and exfiltrate data. We urge everyone using any version of Zammad to update to version 7 or take it offline as soon as possible.”
The vulnerabilities exploited in the attack are remote code execution bug CVE-2026-102489 and elevation of privileges flaw CVE-2026-102490, both of which have a CVSS score of 9.4 when chained.
Read more on agentic AI attacks: Threat Actors Uses Agentic AI to Rapidly Compromise Cloud Target
Fortunately, DIVD’s security expertise meant it was able to contain the threat.
“Thanks to proper network segmentation and the actions of our IT and incident response team after detection, we were able to stop the attackers from going deeper into our systems and network,” it explained. “Unfortunately, some of the damage was already done.”
A separate casefile on the incident explained that volunteer data including DIVD email addresses and possibly contact details was compromised, increasing the risk that malicious actors may try to impersonate DIVD staff.
AI Agent to Blame
On investigating, it became clear that AI was used in the attack, DIVD continued.
“[Logs] show the attacker’s scripts contain notes where the agent justifies its own actions, explaining why what it’s doing is okay and really not phishing, something a human attacker wouldn’t bother with,” it said.
“It supports our assessment that this is an agentic AI-powered attack. We can’t share more for now without getting in the way of the investigation.”
Tim Burke, CEO of consulting firm Quest Technology Management, warned that AI-driven attacks are compressing detection and response timelines.
“For companies without a dedicated SOC, continuous monitoring and visibility matter more. Someone still needs to know what is happening in the environment and be able to act quickly,” he told Infosecurity.
“The broader point is that AI does not replace the fundamentals. It makes patching, monitoring, access controls, air-gapped/immutable data storage, segmentation, and incident response even more important.”
Burke said network segmentation was key to limiting the damage in cases like this, preventing access from spreading across the broader environment.
“The first hour should focus on containment: isolate affected systems, restrict compromised accounts or credentials, block suspicious connections, and stop further movement while the team determines what happened,” he added.
“Organizations should know in advance who has the authority to take those containment actions. Delays matter more when attack activity happens at machine speed.”