On September 21, 2026, attackers breached the Dutch Institute for Vulnerability Disclosure (DIVD) through its Zammad helpdesk. DIVD said the intrusion involved an AI agent and two previously unknown vulnerabilities: one enabled session hijacking and remote code execution, and the other allowed escalation to root. The chain reportedly took seconds. Public reporting describes the attack’s effects, but does not identify the AI system or its operator.
3
9
17
How the Zammad flaws enabled the breach
The attack linked two different weaknesses in Zammad:
- CVE-2026-102489 enabled session hijacking and remote code execution as the local
zammad application user.
3
15
- CVE-2026-102490 enabled a local user to escalate privileges to root. Chained together, the flaws took the attacker from access to the helpdesk to control of its host.
3
15
- From there, the attacker reached other services and copied data. DIVD’s public statements describe access to other services and data exfiltration, but the reporting available here does not establish a complete inventory of systems or data involved.
1
13
DIVD characterized the incident as agentic-AI-powered, and reports describe the activity as loud and messy. Those descriptions do not establish which model or provider was involved, precisely how the agent operated, or who controlled it.
2
17
What DIVD disclosed about detection and response
DIVD said it noticed suspicious activity, investigated, and concluded that its systems had been breached. Its September 24 notice said it had blocked access to its infrastructure, entered incident-response mode, and begun a forensic investigation with outside assistance.
17
On September 30, DIVD disclosed that the Zammad vulnerabilities were the initial access route and published their CVE identifiers while the investigation continued. The available reporting does not specify the exact alert that first surfaced the intrusion or every containment and forensic step.
4
15
16
What Zammad administrators should check
Check the installed release against DIVD’s case advisory. DIVD lists versions 6.3.0–6.5.4 as vulnerable to CVE-2026-102489. Its advisory also lists versions 7.0.0–7.1.3 as affected by that flaw, while noting that environmental conditions prevent exploitation in those releases. For CVE-2026-102490, it lists versions 1.5.0 through 7.1.0-alpha. That means “we run version 7” is not enough to establish that an installation is unaffected.
15
Use DIVD’s current guidance to select the appropriate update or mitigation. The case lists patch status as available and recommends upgrading to Zammad version 7, but its affected-version details distinguish between the two flaws. Check the advisory for the specific release and both CVEs rather than treating a major-version upgrade alone as confirmation that every issue is resolved.
15
Investigate for signs of prior compromise, not just vulnerable software. Review available Zammad, authentication, web-server, and host records for unexpected sessions, code execution under the zammad account, privilege escalation, connections to other services, or unusual data transfers. These checks follow the reported attack chain; the sources do not provide a complete list of forensic indicators.
1
3
15
If there is evidence of root-level access, treat the host and credentials available to it as potentially compromised. Preserve relevant records and investigate before returning the system to service; installing an update by itself does not establish that an earlier intrusion has been contained.