AI Agent Chains Zammad Zero-Days To Take Over DIVD Systems in Seconds
The Dutch Institute for Vulnerability Disclosure, a nonprofit organization of volunteer security researchers whose whole job is finding and responsibly disclosing vulnerabilities in other peopleโs software, just disclosed that it got breached through two zero-days in its own ticketing system.
The attackers got in through Zammad, an open-source helpdesk platform that DIVD used internally. Working with Merlon Security, DIVD identified two previously unknown vulnerabilities, tracked as CVE-2026-102489 and CVE-2026-102490.
Each vulnerability was serious on its own, but chaining them made the attack much more dangerous. The attackers could hijack sessions, run code remotely and move from a regular Zammad account to root access within seconds. DIVD said the speed was linked to the use of an AI agent during the attack.
โWhen hackers get hacked, we deal with it in hacker style. While trying to figure out how the attackers got into our own systems, ๐๐ฒ ๐ณ๐ผ๐๐ป๐ฑ ๐๐๐ผ ๐๐ฒ๐ฟ๐ผ-๐ฑ๐ฎ๐ ๐๐๐น๐ป๐ฒ๐ฟ๐ฎ๐ฏ๐ถ๐น๐ถ๐๐ถ๐ฒ๐ ๐ถ๐ป ๐ญ๐ฎ๐บ๐บ๐ฎ๐ฑ.โ the organization wrote on LinkedIn. โUsed together, they allowed the attackers to hijack sessions, run code remotely and escalate privileges from the Zammad user to root, in seconds, due to the agentic part of this hack. From there they were able to access other services and read and exfiltrate data. We urge everyone using any version of Zammad to update to version 7 or take it offline as soon as possible.โ
The attacker went from the initial access to root privileges in just seconds. The AI agent was able to make decisions and carry out the next steps without waiting for a human operator.
After gaining root access through Zammad, the attacker reached other services, accessed data and stole some of it. Network segmentation and a quick response from DIVDโs IT and incident response teams prevented the attacker from moving further.
However, DIVD said that some damage had already occurred before the attack was stopped. The investigation is still ongoing, with the next public update expected on October 1.
Zammad has over 2,000 customers and 55,000 users. DIVD is actively notifying owners of vulnerable instances and has published a script to check logs for signs of abuse. The fix is version 7, which Zammad considers safe. If you canโt update immediately, the guidance is simple:
โWeโre still in full investigation mode, and our next public statement will be on October 1st. For more information about the CVEs and a script to check your logs for abuse, check our case file. Link in comments.โ the organization states. โIf you run any version of Zammad, update to version 7 or take it offline as soon as possible.โ
The advice from Zammad is clear: update to version 7 or take the system offline. The reason is simple: the attack can move from unauthenticated access to root privileges within seconds, with the AI agent automatically carrying out each step.
The incident also shows that AI-driven attacks are no longer just a theoretical risk. In this case, the agent was able to analyze the environment, chain the two vulnerabilities, gain higher privileges and move to other services without a human directing every action.
DIVD detected the attack partly because it was relatively noisy. The agent left visible traces of its activity, which helped investigators understand what happened. A more careful attacker using the same approach could be harder to detect.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs โ hacking, Zammad)
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content โ general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached โ you'll always get the same 5 for this article.