TRENDING
Close-up of the Rosetta Stone showing the Demotic script above and the Greek script below, the same text written in two different scripts
October 6, 2026
How to Prepare Your Python Code for the Python 3.15 UTF-8 Default and Fix Windows Encoding Bugs
A row of green and grey fibre broadband street cabinets on a pavement beside a fence in Iver, England
October 6, 2026
BT’s TalkTalk Rescue Turns Telecom Continuity Into a New Merger-Control Ground
An ornate cast-iron wall mailbox with its door hanging open, stuffed with colorful flyers and a yellow flyer bulging out of the top slot
October 6, 2026
Google Stops Accepting Product Bug Reports for Its Open-Source Bounty, Citing Automated Submissions
Chronophotograph by Étienne-Jules Marey of a man riding a bicycle, showing five snapshots of the same ride taken at regular intervals
October 6, 2026
How to Find Slow Python Code With the Python 3.15 Tachyon Sampling Profiler
Close-up of an airport baggage tag reading Stockholm Arlanda and ARN
October 6, 2026
Cloudflare Traces Turns Distributed Tracing Into a Trust Decision at the Edge
06 Oct 2026
SXZ.io SXZ.io
  • Home
Search the Site
Popular Searches:
Technology Amazon AI
Recent Posts
Shelves of old books fastened by iron chains in the Francis Trigge Chained Library in Grantham, England, a picture of data that can be read but not changed
How to Use frozendict in Python 3.15 to Freeze Config and Cache Dictionary Arguments
October 5, 2026
Row of capsule hotel pods with white pillows and folded blankets, each capsule an idle sleeper packed into a shared rack
Kubernetes Node Swap Turns Idle Agent Memory Into a Density Bet With No Wake-Up Test
October 5, 2026
Denmark’s oldest church book, from Holmens parish, open on a stack of books; its handwritten pages record births between 1617 and 1639
Denmark Says 8.8 Million Population Register Records Were Pulled Through One Company’s Lawful Access
October 5, 2026
SXZ.io SXZ.io
  • Home

Categories

Articles 226 Posts
News 228 Posts
Learning Hub 198 Posts
Home/News/DIVD Says Two Zammad Zero-Days Let an AI Agent Climb From Session Hijack to Root in Seconds
News

DIVD Says Two Zammad Zero-Days Let an AI Agent Climb From Session Hijack to Root in Seconds

Dutch nonprofit DIVD says two Zammad zero-days, CVE-2026-102489 and CVE-2026-102490, let an AI agent go from a hijacked session to root in seconds.

October 1, 2026 5 Min Read
23

The Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit of volunteer security researchers that warns other organizations about exposed systems, has been breached itself. After almost seven years, DIVD wrote, “we’re the hackers that got hacked.” On September 30 it explained how: through two previously unknown flaws in Zammad, an open-source helpdesk and ticketing platform, abused by attackers who let an AI agent drive the intrusion. Used together, DIVD says, the bugs let them hijack sessions, run code remotely and “escalate privileges from the Zammad user to root, in seconds, due to the agentic part of this hack.”

Table Of Content

  • What DIVD has confirmed
  • The two flaws
  • What the agent did
  • What is still unclear
  • What admins can do now
  • Why it matters

The story was still moving on October 1. As of this writing, DIVD’s promised overview of which data was compromised had not appeared, and Zammad’s public GitHub advisories listed nothing for either bug.

What DIVD has confirmed

DIVD’s case file DIVD-2026-00014 sets out the timeline. The attacker’s first access was on September 21. DIVD noticed malicious activity the next day, blocked access to all systems in its datacenter, formed an incident response team and started a forensic investigation together with Merlon Security. On September 24 it went public, writing that the “modus operandi indicates that this is an agentic AI powered attack,” that it had informed the Dutch data protection authority (the Autoriteit Persoonsgegevens) and the National Cyber Security Centre, and that it would “assume breach until proven otherwise.”

A second file, DIVD-2026-00015, covers the two vulnerabilities found along the way. DIVD says it analyzed and reproduced them on September 22 and 23, reported them to Zammad on September 24, scanned for exposed Zammad servers on September 26 and began notifying their owners the same day, then published both files and the CVE records on September 30. The investigation is still open. According to BleepingComputer, network segmentation and the incident response kept the attacker from moving deeper into the network. DIVD’s own statement, quoted by Security Affairs, says that before that point the attackers were able to access other services and “read and exfiltrate data.”

The two flaws

CVE What it does Versions DIVD lists CVSS 4.0
CVE-2026-102489 Session hijack that leads to remote code execution as the zammad user Exploitable in 6.3.0 to 6.5.4; present in 7.0.0 to 7.1.3 but “not exploitable due to environment conditions” 9.4
CVE-2026-102490 Local escalation from the zammad user to root v1.5.0 up to v7.1.0-alpha on the case page; the CVE text says “All versions of Zammad including the latest alpha” 9.4

DIVD, which is a CVE Numbering Authority, published both records on September 30 with the same CVSS 4.0 vector: network attack, low complexity, no privileges required, “passive” user interaction, and an exploit-maturity rating of “Attacked.” NVD lists both as “Deferred” and has not scored them itself, and CISA’s Known Exploited Vulnerabilities catalog (version 2026.09.30) does not include either. Because the second bug is described as a local escalation yet carries the same network vector and 9.4 score as the first, the numbers read as DIVD rating the chain as it was used rather than each flaw on its own. The root-escalation step still needs a foothold first, as its own description says.

What the agent did

DIVD has been unusually open about how the intruder behaved. In its Monday update, as quoted by BleepingComputer, it said “the attack itself was loud and very very messy” and that “after every action it decided the next step itself, at the speed of light and sloppy logic or pattern.” BleepingComputer reports that the agent did “some pretty dumb things,” including interfering with its own adversary-in-the-middle attack through password spraying, that it over-explained its decisions in its comments, and that DIVD believes it was poorly trained and configured for such operations. The same report says DIVD specifically ruled out Citrix NetScaler as the vulnerable system, at a time when two NetScaler zero-days were in the news.

That sloppiness is what made the investigation possible. BleepingComputer says the agent left behind clear explanations of its decisions, which let DIVD reconstruct the incident.

What is still unclear

Who found the bugs. Public statements do not say whether the agent discovered the Zammad flaws, was pointed at them by a human operator, or ran a ready-made exploit. BleepingComputer’s September 29 report described an attacker who exploited a vulnerability and then used an automated AI agent for post-exploitation activity, while DIVD’s September 30 statement credits the speed of the chain to “the agentic part of this hack.” None of the statements reviewed names the attacker, the model behind the agent or the purpose of the intrusion.

What data left. DIVD’s case file listed October 1 as the planned date for an overview of which data is compromised and which is not. Security Affairs reports that some damage had already occurred before the attack was stopped.

Which release closes the holes. DIVD’s case page recommends “Upgrade to Zammad version 7,” lists the patch status as “Available” and the workaround as “N/A,” but also says it reported the problem to Zammad, “who are working on a fix.” The page lists the root-escalation bug as affecting v1.5.0 up to v7.1.0-alpha, while the CVE text says all versions including the latest alpha are affected. Zammad’s public GitHub security advisories list no entry for either CVE; the newest were published on August 25 and cover versions up to 7.1.2. Until Zammad publishes its own advisory, “version 7” is DIVD’s recommendation rather than a vendor-confirmed fixed release.

How widely Zammad is used. Zammad’s homepage describes the project as “Loved by over 2,000 organizations and 50,000+ users worldwide.” DIVD says it is scanning for vulnerable instances and alerting their owners, and the case page gives no count of how many it found.

What admins can do now

DIVD’s advice is blunt: if you run any version of Zammad, “update to version 7 or take it offline as soon as possible.” It says its case file offers a script for checking Zammad log files for indicators of compromise. Because the chain ends in root, patching alone will not undo an earlier compromise, which is what the log check is for.

Why it matters

Spain’s data protection agency said on September 14 that it had received its first breach notification in which an AI agent allegedly carried out most of the attack, and ThreatDown’s Carbonato research showed an off-the-shelf agent running as a botnet’s operator console. The DIVD case differs because the victim has documented it itself: a named organization, two CVE records, a dated timeline and an agent that narrated its own steps.

For defenders the lesson is about time. When a hijacked session becomes root in seconds, a patch window measured in days and detection that relies on a person reading logs are a poor match for this style of attack. This agent’s sloppiness is why DIVD could reconstruct what happened; as Security Affairs notes, a more careful attacker using the same approach could be harder to detect.

Three things to watch next: DIVD’s promised overview of the compromised data, a Zammad advisory that names fixed releases for both CVEs, and whether NVD scores the records or CISA adds them to its catalog.

Tags:

Agentic AIAI AgentsData BreachesDIVDZammadZero-Day

Share

Faint white watermark of a crown above an oval emblem showing through blue paper, a design that stays invisible until light passes through the sheet
Previous Post

How to Detect and Strip Invisible Unicode in Python to Stop ASCII Smuggling and Trojan Source

A red emergency stop button on a factory control panel, a literal kill switch
Next Post

Paragon’s CEO Turns Spyware Ethics Into a Promise the Vendor Cannot Audit

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest
05 Oct
How to Use frozendict in Python 3.15 to Freeze Config and Cache Dictionary Arguments
05 Oct
Kubernetes Node Swap Turns Idle Agent Memory Into a Density Bet With No Wake-Up Test
Trending
October 5, 2026
How to Use frozendict in Python 3.15 to Freeze Config and Cache Dictionary Arguments
October 5, 2026
Kubernetes Node Swap Turns Idle Agent Memory Into a Density Bet With No Wake-Up Test
October 5, 2026
Denmark Says 8.8 Million Population Register Records Were Pulled Through One Company’s Lawful Access
October 5, 2026
How to Prepare Your Python Code for the Python 3.15 UTF-8 Default and Fix Windows Encoding Bugs
October 5, 2026
BT’s TalkTalk Rescue Turns Telecom Continuity Into a New Merger-Control Ground
October 5, 2026
Google Stops Accepting Product Bug Reports for Its Open-Source Bounty, Citing Automated Submissions

Related Posts

Rows of server racks in a data center representing network infrastructure targeted by botnets
News

C0XMO Botnet Shows Why Old Router Firmware Still Matters

June 7, 2026
Close-up of a USB flash drive, representing physical data-theft risk in office security incidents
News

Fake IT Support Is Now Walking Through the Front Door

June 7, 2026
A phone security app on a smartphone resting on a laptop keyboard.
News

Everest Forms Pro Flaw Is Being Exploited to Create Rogue WordPress Admins

June 7, 2026
A customer-support representative wearing a headset against a dark studio background.
Articles

The Meta AI Support Hack Was a Plain Old Authorization Failure

June 7, 2026
SXZ.io SXZ.io
  • [email protected]

Categories

Articles
Learning Hub
News

All Rights Reserved by SXZ.io ©2026