Autonomous AI agent breached DIVD using two Zammad zero-days
An autonomous AI agent chained two Zammad zero-days to root Dutch nonprofit DIVD and steal volunteer email addresses.
The Dutch Institute for Vulnerability Disclosure (DIVD) said an autonomous AI agent breached its network after seven years without incident by chaining two Zammad helpdesk zero-days, CVE-2026-102489 and CVE-2026-102490. SecurityWeek, Help Net Security, and The Register date the compromise to September 21, 2026, while Infosecurity Magazine says suspicious activity was noticed on September 24. The flaws were used to hijack or leak sessions, run code as the Zammad user, and escalate to root within seconds, then reach other services and exfiltrate data; The Register and Infosecurity say that included volunteer email addresses and possibly other contact details, while DIVD’s first notice left impact unclear and said only that the bug was not Citrix NetScaler. CVE-2026-102489 is unauthenticated remote code execution with session leakage in Zammad 6.3.0–6.5.4, and CVE-2026-102490 is local escalation to root; SecurityWeek rates each CVSS 9.4, while The Register and Infosecurity describe a chained CVSS 9.4 score, and sources disagree on 7.x—SecurityWeek says 7.0.0–7.1.3 contain the bugs but are not exploitable as deployed, whereas Help Net Security says only CVE-2026-102489 is non-exploitable there and CVE-2026-102490 affects every version, including the latest alpha, with no fix published. DIVD called the intrusion loud and messy, citing password spraying that disrupted the agent’s own adversary-in-the-middle attack and self-commenting scripts, and with Merlon Security urges more than 2,000 customers and 55,000 users to move to Zammad 7 or take instances offline. Segmentation and response limited deeper access, but DIVD assumes a breach, notified Dutch police, the data protection authority, and NCSC-NL, published a log-hunting script, and says the investigation continues; SecurityWeek adds that Zammad is preparing fixes.
- DIVD was breached by an autonomous AI agent after seven quiet years; SecurityWeek, Help Net Security, and The Register date the compromise to September 21, 2026, while Infosecurity Magazine says suspicious activity was noticed on September…
- CVE-2026-102489 is unauthenticated remote code execution and session leakage in Zammad 6.3.0–6.5.4; CVE-2026-102490 is local-to-root escalation. SecurityWeek rates each CVSS 9.4; The Register says both scored CVSS 4.0 9.4 when chained.
- The agent reached root within seconds, pivoted to other services, and exfiltrated data that The Register and Infosecurity identify as volunteer email addresses and possibly other contact details.
- On Zammad 7.0.0–7.1.3, SecurityWeek says the bugs are present but not exploitable as deployed; Help Net Security says only CVE-2026-102489 is non-exploitable there and that CVE-2026-102490 affects all versions, including the latest alpha,…
Coverage timelineoldest first · each row is one article
- · 3d agoAutomated AI agent used to breach cybersecurity nonprofit DIVD
BleepingComputer· 68
DIVD says an autonomous AI agent exploited a flaw and performed a messy intrusion on its network.
- · 1d agoDIVD says Zammad zero-days enabled AI-driven network breach
BleepingComputer· 76
An autonomous AI agent used two Zammad zero-days to breach DIVD, gain root, and exfiltrate data within seconds.
- · 1d agoAI Agent Chains Zammad Zero-Days To Take Over DIVD Systems in Seconds
Security Affairs· 80
Vulnerabilities in this storyAll →
- CVE-2026-1024899.4<1%Session hijack to RCE in Zammadpublished · Zammad KEV+1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
CVE-2026-102489+1 related CVE |