Two Zammad zero-days chained in DIVD breach added to CISA KEV
Attackers reportedly used an AI agent to chain two Zammad zero-days, root DIVD, and steal volunteer contacts; CISA set a 5 October 2026 fix deadline.
The Dutch Institute for Vulnerability Disclosure was breached when attackers chained Zammad zero-days CVE-2026-102489 and CVE-2026-102490, reached root within seconds, and exfiltrated volunteer email addresses and possibly other contact details; one account also says a security-ticket archive may have been partly extracted and that password spraying followed. Sources disagree on timing: several place the intrusion on 21 September 2026, while others say activity was noticed or the breach disclosed on 24 September, and one says detection came the next day with theft confirmed by 1 October. CVE-2026-102489, described as session hijacking or session disclosure that can yield remote code execution as the Zammad user, affects 6.3.0 through 6.5.4 and is present but reportedly not exploitable as tested in 7.0.0–7.1.3; CVE-2026-102490 escalates that user to root from 1.5.0 through 7.1.0-alpha. Score reporting conflicts: Security Affairs lists both CVEs at CVSS 9.4, later reports assign 8.7 and 8.5 individually and 9.4 to the chain, and Horizon3.ai scores CVE-2026-102489 at 9.8. CISA added both flaws to its Known Exploited Vulnerabilities catalog on 2 October 2026, with a federal deadline of 5 October 2026 under BOD 26-04. DIVD urged updating to version 7 or taking systems offline, but the privilege-escalation bug still affects some version 7 builds; Sysdig advises 7.0.0 or later, ideally 7.2.0, while Zammad recommends 7.2.0 or later and says 6.5 and earlier are unsupported. Reporting attributes the intrusion to an AI agent, cites more than 2,000 Zammad customers and 55,000 users, and notes Horizon3.ai released a proof of concept for CVE-2026-102489 on 7 October while withholding details of the related escalation.
- CVE-2026-102489 (session hijacking or disclosure leading to remote code execution as the Zammad user) affects 6.3.0–6.5.4 and is also present, but reportedly not exploitable as tested, in 7.0.0–7.1.3.
- CVE-2026-102490 escalates the Zammad user to root on versions 1.5.0 through 7.1.0-alpha; sources say the chain reached root within seconds.
- Timing disagrees: several outlets date the DIVD compromise to 21 September 2026; others cite activity noticed or disclosure on 24 September; one says detection the next day and confirmed email theft by 1 October, with a ticket archive…
- CVSS figures conflict: both flaws listed at 9.4; later reports give 8.7 and 8.5 individually and 9.4 for the chain; Horizon3.ai scores CVE-2026-102489 at 9.8.
- CISA added both CVEs to the KEV catalog on 2 October 2026, with a federal deadline of 5 October 2026 under BOD 26-04.
Coverage timelineoldest first · each row is one article
- · 6d agoTwo Zero-Days Exploited in Attack on Dutch Institute for Vulnerability Disclosure
Infosecurity Magazine· 76
Attackers exploited two Zammad zero-days to breach DIVD, reach root, and steal volunteer contact data.
- · 6d agoZammad 0-Day Vulnerabilities Exploited to Gain Remote Code Execution and Root Access
Cyber Security News· 80
Attackers exploited two Zammad zero-days for remote code execution and root, including a breach of DIVD.
- · 6d ago
Vulnerabilities in this storyAll →
- CVE-2026-1024899.41%Session hijack to RCE in Zammadpublished · Zammad KEV PoC +1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected |
|---|