TWO zero-day flaws in the Zammad helpdesk platform were exploited to compromise the Dutch Institute for Vulnerability Disclosure (DIVD), a Dutch cybersecurity non-profit. The attack, detected on 24 September and disclosed on 30 September, used two chained vulnerabilities—remote code execution CVE-2026-102489 and privilege escalation CVE-2026-102490—both with a CVSS of 9.4, to hijack sessions, run code remotely and elevate privileges from a Zammad user to root within seconds.
DIVD warned that users should update to version 7 or take the platform offline to mitigate the risk. The vulnerabilities allowed attackers to access other services and read and exfiltrate data, with the DIVD stating that some damage had already been done.
DIVD’s security measures helped contain the incident through proper network segmentation and incident response actions, preventing deeper access, though volunteer data, including DIVD email addresses and possibly contact details, was compromised, raising the risk of impersonation of DIVD staff. Investigators found that AI played a role in the attack, with logs indicating that the attacker’s scripts included notes justifying their actions and describing why the activity was not phishing.
Experts emphasised that while AI can accelerate breaches, fundamental security practices—patching, monitoring, access controls, segmentation, and robust incident response—remain essential. Practically, containment within the first hour was highlighted as crucial to limit movement, and organisations are urged to predefine who may authorize containment actions to avoid delays.