DIVD says an attacker broke into its systems through two previously unknown vulnerabilities in its Zammad helpdesk. The attack progressed from session hijacking to code execution and root access within seconds. DIVD describes the activity as indicative of an AI-agent-powered attack, but the available public evidence does not establish who controlled the attacker or how closely a person supervised it.
5
7
How the attack unfolded
The first flaw, CVE-2026-102489, enabled session hijacking and remote code execution as the local zammad user. The second, CVE-2026-102490, allowed that user to escalate privileges to root on the helpdesk host. DIVD says the attacker could then access other services and exfiltrate data.
5
18
DIVD’s timeline begins on September 21, 2026, with the initial intrusion. The organization detected suspicious activity the following day, blocked access to its data-centre infrastructure and began a forensic investigation with incident-response firm Merlon Security. It publicly acknowledged the breach on September 24 and later published separate incident and vulnerability case details.
7
10
17
What was exposed—and what is still unclear
DIVD reported that email addresses belonging to volunteer security researchers were exposed. Public reporting also refers to the possibility of other contact details, but the available evidence does not establish the complete amount or type of data taken, or confirm that every DIVD system was compromised.
5
8
DIVD’s description of the attack as “agentic” reflects its assessment of the attack’s behavior. Public information has not identified the attacker or the AI agent or service involved, nor established whether a human approved individual actions or simply set an objective for the agent. The label should not be taken as proof that the intrusion operated without human involvement.
5
7
What Zammad administrators should do
Preserve evidence before updating
Copy application and network logs before installing updates, as recommended in reporting on the incident. Review activity from September 21 onward for unusual sessions, unexpected activity by the zammad account, privilege escalation and suspicious outbound transfers. These are investigation areas, not a published, complete set of indicators of compromise; an update alone cannot show whether a system was previously accessed.
1
5
Check both vulnerabilities and the exact release
DIVD identifies Zammad versions 6.3.0–6.5.4 as vulnerable to the session-hijacking and code-execution path. The same vulnerable code is present in 7.0.0–7.1.3, although DIVD says it was not exploitable in those releases under the environmental conditions it assessed.
18
Do not assume that moving to version 7 resolves the entire chain. CVE-2026-102490 is a separate local privilege-escalation flaw affecting the zammad user, and reporting says a version 7 upgrade does not by itself fix it. Check the current Zammad and DIVD advisories for the precise remediation status of each issue. If an exposed instance cannot be secured promptly, take it offline while you investigate and remediate.
1
18
If you find evidence of root access, treat the host as compromised and investigate beyond the helpdesk application. DIVD’s public case says the attacker could reach other services, while the published reporting does not provide a complete set of compromise indicators or establish the full scope of exfiltration.
5
1