DIVD Breach Traced to Two Zammad Zero-Day Vulnerabilities Exploited by AI Agent

Dutch security nonprofit says chain of flaws allowed session hijacking, remote code execution, and root escalation in seconds

By LineZotpaper
Published
Read Time2 min
The Dutch Institute for Vulnerability Disclosure (DIVD) has identified two zero-day vulnerabilities in the open-source Zammad ticketing system as the entry point for a recent network breach, in which an autonomous AI agent executed a chain of exploits in seconds.

The Dutch Institute for Vulnerability Disclosure (DIVD) has confirmed that a breach of its network was made possible by exploiting two zero-day vulnerabilities in the open-source Zammad ticketing platform. The flaws, tracked as CVE-2026-102489 and CVE-2026-102490, enabled attackers to hijack sessions, execute code remotely, and escalate privileges from the Zammad user to root.

DIVD previously described the attack as “loud and very, very messy,” driven by an AI agent that moved autonomously and determined its next steps without human intervention. The organization was able to reconstruct the incident in detail because the AI agent left behind clear explanations of its decisions.

According to DIVD, the two vulnerabilities were used together, allowing the attacker to access other services, read and exfiltrate data in a matter of seconds. However, due to network segmentation and incident response actions, the threat actor did not move deeper into the network. The investigation remains ongoing.

DIVD discovered the zero-days in collaboration with Merlon Security and notified Zammad, the open-source AI-powered helpdesk and support ticketing platform. Zammad claims on its website to serve over 2,000 customers and 55,000 users, including De’Longhi, Amnesty International, and NextCloud.

DIVD recommends that Zammad users upgrade to version 7, which is considered safe, or take their instances offline as soon as possible. The organization has promised to share additional updates about the incident tomorrow.

§

Analysis

Why This Matters

  • The attack demonstrates how AI agents can chain multiple zero-day vulnerabilities to achieve full system compromise in seconds, raising the bar for defenders.
  • Zammad is used by over 2,000 organizations, including major brands; vulnerable instances may be at risk if not patched promptly.
  • The incident provides a rare detailed reconstruction of an AI-driven attack, offering valuable intelligence for the cybersecurity community.

Background

DIVD is a nonprofit organization of volunteer security researchers focused on vulnerability disclosure. Zammad is an open-source, AI-powered helpdesk and ticketing system available as self-hosted or hosted service. The attack relied on two previously unknown flaws in Zammad that together allowed privilege escalation to root.

Key Perspectives

DIVD: Emphasizes the severity of the exploit chain and the speed of the AI-driven attack, while noting that network segmentation limited deeper damage. Zammad users: Must urgently assess whether their instances are on a vulnerable version and apply the recommended upgrade to version 7. Security researchers: See the incident as a case study in agentic attacks, highlighting the need for faster patching cycles and AI-aware defenses.

What to Watch

  • Further details from DIVD's promised update on the full scope of data exfiltration.
  • Whether additional Zammad vulnerabilities are discovered in the wake of this disclosure.
  • Adoption rate of version 7 among Zammad's customer base and any reports of follow-on attacks targeting unpatched instances.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.