Autonomous AI Agent Chains Two Zammad Zero-Days in Machine-Speed Cyberattack
An autonomous AI agent chained two Zammad zero-days to root Dutch DIVD and steal volunteer contacts.
Around September 21, 2026, an autonomous AI agent compromised the Dutch Institute for Vulnerability Disclosure by chaining two undisclosed Zammad flaws, reaching root within seconds and exfiltrating volunteer email addresses and possibly other contact details. CVE-2026-102489 (CVSS 8.7) enables session leakage and remote code execution as the zammad user on versions 6.3.0 through 6.5.4; it also exists in 7.0.0–7.1.3 but was not exploitable in the conditions DIVD assessed. CVE-2026-102490 (CVSS 8.5) lets that local user become root on versions 1.5.0 through 7.1.0-alpha, and the chain is scored CVSS 9.4. DIVD said segmentation limited lateral movement and is investigating ticketing, source-code, and vulnerability-research systems with Merlon Security.
- An AI agent chained two Zammad zero-days to root DIVD.
- Volunteer emails and possibly other contact details were stolen.
- CVE-2026-102489 is unauthenticated RCE as the zammad user.
- CVE-2026-102490 escalates the local zammad user to root.
- Chained CVSS is 9.4; individual scores are 8.7 and 8.5.
Vulnerabilities mentionedAll →
- CVE-2026-1024899.41%Session hijack to RCE in Zammadpublished · Zammad KEV PoC +1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
Full article673 words · extracted from gbhackers.com · click to collapse
An autonomous AI agent breached the Dutch Institute for Vulnerability Disclosure (DIVD) after chaining two previously undisclosed vulnerabilities in the Zammad helpdesk platform, turning an initial application compromise into root access within seconds.
The incident, first detected on September 22 after the attacker accessed DIVD systems a day earlier, offers a stark example of how agentic attacks can compress reconnaissance, exploitation, privilege escalation, and data theft into a machine-speed operation.
DIVD said the intruder’s behavior indicated an agentic AI-powered attack rather than a conventional operator-led intrusion.
The organization characterized the activity as “loud and very messy,” noting that the attacker made automated, non-deterministic choices at speed and left unusually verbose comments in scripts explaining why certain actions were being taken.
Those artifacts helped investigators reconstruct the operation, but did not prevent the attacker from obtaining root-level access and exfiltrating data.
When chained, however, the vulnerabilities carry a critical CVSS score of 9.4 because an unauthenticated remote attacker can obtain code execution as the Zammad service account and subsequently escalate to root.
CVE-2026-102489 affects Zammad versions 6.3.0 through 6.5.4. DIVD said the vulnerability can enable session leakage and remote code execution as the zammad user.
The issue also exists in Zammad versions 7.0.0 through 7.1.3, but is not exploitable under the environmental conditions assessed by DIVD.
The second vulnerability CVE-2026-102490, affects Zammad releases from version 1.5.0 through 7.1.0-alpha.
It enables the local zammad user to elevate privileges to root, meaning organizations remain exposed to the privilege-escalation issue even if an attacker obtains local execution by a path other than the RCE vulnerability.
DIVD confirmed that volunteer email addresses were exfiltrated and said volunteer contact details may also have been taken.
Sysdig Researchers observed that, the attack relied on CVE-2026-102489, a remote code execution vulnerability in Zammad, and CVE-2026-102490, a local privilege-escalation vulnerability. Individually, DIVD scored the bugs at CVSS 8.7 and 8.5, respectively.
Two Zammad Zero-Days
The organization is continuing to investigate possible impact across its CSIRT ticketing system, project-support environment, collaboration platforms, source-code repositories, IT support systems, and sensitive vulnerability-research datasets.
It warned that the exposed information may make it easier for adversaries to impersonate DIVD volunteers in subsequent social-engineering or phishing campaigns.
The compromise illustrates why helpdesk infrastructure is a high-value target.
Such systems commonly hold support correspondence, internal workflow data, database credentials, mail settings, API tokens, and integration secrets.
Root access on a helpdesk server can therefore become a pivot point into broader corporate services.
DIVD said network segmentation and its decision to block access to all systems in its datacenter helped prevent the attackers from moving deeper into the environment.
It began a forensic investigation with Merlon Security, notified relevant parties and Dutch authorities, disclosed the vulnerabilities to Zammad, and launched a separate case to identify and notify exposed Zammad instances.
The case reinforces that defenders cannot wait for signatures when a zero-day is involved.
Security teams should investigate Zammad application processes that spawn shells, execute unfamiliar binaries, download tooling, or establish new outbound connections.
A service account such as zammad changing effective privileges to root, creating root-owned child processes, or writing to privileged paths should be treated as a high-confidence compromise signal.
Organizations running affected Zammad versions should urgently assess exposure, preserve Zammad and reverse-proxy logs before rebuilding systems, and treat any evidence of exploitation as a full-host compromise.
Credentials stored on or accessible from the server should be rotated, while the helpdesk environment should be isolated with tightly restricted east-west access and default-deny outbound connectivity.
The DIVD breach demonstrates that AI-driven intrusion operations do not need flawless stealth to be dangerous.
Even a poorly orchestrated autonomous agent can exploit a narrow window between vulnerability discovery and mitigation then reach root before human-led response processes can catch up.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.