THE Dutch Institute for Vulnerability Disclosure (DIVD) says it was hacked in an automated AI-powered attack that exploited two zero-day vulnerabilities in the open-source Zammad web-based ticketing system. The breach occurred on 21 September, prompting full incident response and a temporary block on DIVD’s infrastructure.
DIVD describes the operation as an agentic AI-powered attack and notes that the attackers pivoted from the Zammad instance to other services and exfiltrated data, though network segmentation halted deeper access. Investigation identified two zero-days used for initial access and escalation: CVE-2026-102489, with a CVSS of 9.4, enabling unauthenticated remote code execution and user-session leakage; and CVE-2026-102490, also CVSS 9.4, allowing a local user to elevate privileges to root. When used together, they allowed session hijacking, remote code execution, and rapid privilege escalation.
DIVD states that Zammad versions 6.3.0–6.5.4 are affected, and versions 7.0.0–7.1.3 also contain the defects, though exploitation is not possible in the latter due to environment conditions. The institute has urged all Zammad users to upgrade to version 7 or take the service offline, and it has published a verification script to hunt for IoCs and is actively scanning for vulnerable instances and alerting owners. DIVD reported the incidents to Zammad, which is developing a fix, and notes that, while attackers were halted, the breach is still under investigation.