DIVD Says Two Zammad Zero-Days Let an AI Agent Climb From Session Hijack to Root in Seconds
Dutch nonprofit DIVD says two Zammad zero-days, CVE-2026-102489 and CVE-2026-102490, let an AI agent go from a hijacked session to root in seconds.
The Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit of volunteer security researchers that warns other organizations about exposed systems, has been breached itself. After almost seven years, DIVD wrote, “we’re the hackers that got hacked.” On September 30 it explained how: through two previously unknown flaws in Zammad, an open-source helpdesk and ticketing platform, abused by attackers who let an AI agent drive the intrusion. Used together, DIVD says, the bugs let them hijack sessions, run code remotely and “escalate privileges from the Zammad user to root, in seconds, due to the agentic part of this hack.”
Table Of Content
The story was still moving on October 1. As of this writing, DIVD’s promised overview of which data was compromised had not appeared, and Zammad’s public GitHub advisories listed nothing for either bug.
What DIVD has confirmed
DIVD’s case file DIVD-2026-00014 sets out the timeline. The attacker’s first access was on September 21. DIVD noticed malicious activity the next day, blocked access to all systems in its datacenter, formed an incident response team and started a forensic investigation together with Merlon Security. On September 24 it went public, writing that the “modus operandi indicates that this is an agentic AI powered attack,” that it had informed the Dutch data protection authority (the Autoriteit Persoonsgegevens) and the National Cyber Security Centre, and that it would “assume breach until proven otherwise.”
A second file, DIVD-2026-00015, covers the two vulnerabilities found along the way. DIVD says it analyzed and reproduced them on September 22 and 23, reported them to Zammad on September 24, scanned for exposed Zammad servers on September 26 and began notifying their owners the same day, then published both files and the CVE records on September 30. The investigation is still open. According to BleepingComputer, network segmentation and the incident response kept the attacker from moving deeper into the network. DIVD’s own statement, quoted by Security Affairs, says that before that point the attackers were able to access other services and “read and exfiltrate data.”
The two flaws
| CVE | What it does | Versions DIVD lists | CVSS 4.0 |
|---|---|---|---|
| CVE-2026-102489 | Session hijack that leads to remote code execution as the zammad user | Exploitable in 6.3.0 to 6.5.4; present in 7.0.0 to 7.1.3 but “not exploitable due to environment conditions” | 9.4 |
| CVE-2026-102490 | Local escalation from the zammad user to root | v1.5.0 up to v7.1.0-alpha on the case page; the CVE text says “All versions of Zammad including the latest alpha” | 9.4 |
DIVD, which is a CVE Numbering Authority, published both records on September 30 with the same CVSS 4.0 vector: network attack, low complexity, no privileges required, “passive” user interaction, and an exploit-maturity rating of “Attacked.” NVD lists both as “Deferred” and has not scored them itself, and CISA’s Known Exploited Vulnerabilities catalog (version 2026.09.30) does not include either. Because the second bug is described as a local escalation yet carries the same network vector and 9.4 score as the first, the numbers read as DIVD rating the chain as it was used rather than each flaw on its own. The root-escalation step still needs a foothold first, as its own description says.
What the agent did
DIVD has been unusually open about how the intruder behaved. In its Monday update, as quoted by BleepingComputer, it said “the attack itself was loud and very very messy” and that “after every action it decided the next step itself, at the speed of light and sloppy logic or pattern.” BleepingComputer reports that the agent did “some pretty dumb things,” including interfering with its own adversary-in-the-middle attack through password spraying, that it over-explained its decisions in its comments, and that DIVD believes it was poorly trained and configured for such operations. The same report says DIVD specifically ruled out Citrix NetScaler as the vulnerable system, at a time when two NetScaler zero-days were in the news.
That sloppiness is what made the investigation possible. BleepingComputer says the agent left behind clear explanations of its decisions, which let DIVD reconstruct the incident.
What is still unclear
Who found the bugs. Public statements do not say whether the agent discovered the Zammad flaws, was pointed at them by a human operator, or ran a ready-made exploit. BleepingComputer’s September 29 report described an attacker who exploited a vulnerability and then used an automated AI agent for post-exploitation activity, while DIVD’s September 30 statement credits the speed of the chain to “the agentic part of this hack.” None of the statements reviewed names the attacker, the model behind the agent or the purpose of the intrusion.
What data left. DIVD’s case file listed October 1 as the planned date for an overview of which data is compromised and which is not. Security Affairs reports that some damage had already occurred before the attack was stopped.
Which release closes the holes. DIVD’s case page recommends “Upgrade to Zammad version 7,” lists the patch status as “Available” and the workaround as “N/A,” but also says it reported the problem to Zammad, “who are working on a fix.” The page lists the root-escalation bug as affecting v1.5.0 up to v7.1.0-alpha, while the CVE text says all versions including the latest alpha are affected. Zammad’s public GitHub security advisories list no entry for either CVE; the newest were published on August 25 and cover versions up to 7.1.2. Until Zammad publishes its own advisory, “version 7” is DIVD’s recommendation rather than a vendor-confirmed fixed release.
How widely Zammad is used. Zammad’s homepage describes the project as “Loved by over 2,000 organizations and 50,000+ users worldwide.” DIVD says it is scanning for vulnerable instances and alerting their owners, and the case page gives no count of how many it found.
What admins can do now
DIVD’s advice is blunt: if you run any version of Zammad, “update to version 7 or take it offline as soon as possible.” It says its case file offers a script for checking Zammad log files for indicators of compromise. Because the chain ends in root, patching alone will not undo an earlier compromise, which is what the log check is for.
Why it matters
Spain’s data protection agency said on September 14 that it had received its first breach notification in which an AI agent allegedly carried out most of the attack, and ThreatDown’s Carbonato research showed an off-the-shelf agent running as a botnet’s operator console. The DIVD case differs because the victim has documented it itself: a named organization, two CVE records, a dated timeline and an agent that narrated its own steps.
For defenders the lesson is about time. When a hijacked session becomes root in seconds, a patch window measured in days and detection that relies on a person reading logs are a poor match for this style of attack. This agent’s sloppiness is why DIVD could reconstruct what happened; as Security Affairs notes, a more careful attacker using the same approach could be harder to detect.
Three things to watch next: DIVD’s promised overview of the compromised data, a Zammad advisory that names fixed releases for both CVEs, and whether NVD scores the records or CISA adds them to its catalog.








No Comment! Be the first one.