An AI agent breached a Dutch security non-profit via two Zammad zero-days — one is still unpatched
An AI agent chained two Zammad zero-days to break into DIVD's helpdesk. Both are now on CISA's exploited list, and the root flaw is still unpatched.
An attacker that the Dutch Institute for Vulnerability Disclosure (DIVD) describes as an autonomous AI agent broke into the non-profit's Zammad helpdesk on September 21, 2026, using two flaws nobody knew about. Both are now on the US Cybersecurity and Infrastructure Security Agency's (CISA) list of actively exploited vulnerabilities. If you run a self-hosted Zammad, upgrade to 7.2.0 now and check your logs: the remote-code flaw only bites on 6.5 and older, but the root-escalation flaw has no released fix yet.
What happened, in plain English
DIVD is a Dutch volunteer organisation that scans the internet for vulnerable systems and warns their owners. On September 21, 2026, someone got into its ticketing system, Zammad, an open-source helpdesk used by many IT teams and service desks. DIVD spotted the activity on September 22 and cut off access to its data centre.
The attacker chained two weaknesses. The first let them take over a logged-in user's session and run commands on the server as the "zammad" service account. The second let that service account make itself "root", the all-powerful administrator account on Linux. DIVD says the two together got the attacker from outside to root "in seconds".
What makes this case unusual is who, or what, did it. DIVD concluded it was an agentic AI attack: software driven by a large language model (LLM) that decides its own next steps. Its scripts contained notes in which the agent justified its own actions, and DIVD describes the operation as fast, automated, verbose and sloppy.
Think of a burglar who works very fast but narrates every move into a dictaphone and leaves the tape behind. That narration helped DIVD's investigators.
Volunteer email addresses, and possibly contact details, were taken. Network segmentation kept the attacker away from DIVD's other systems.
Are you affected? What to do now
Who should care: anyone running a self-hosted Zammad server. If your helpdesk is a different product, there is nothing to patch here. If you use Zammad's hosted service, ask Zammad for confirmation. Neither DIVD nor Zammad has published a statement about hosted instances that we could find.
Where things stand (from the primary sources):
- CVE-2026-102489: session takeover leading to remote code execution as the zammad user. CISA lists it as a session fixation flaw (CWE-384). DIVD says it can be exploited in versions 6.3.0 to 6.5.4, and is present but not exploitable in 7.0.0 to 7.1.3. Zammad says exploitation is only possible on 6.5 and older "because of the runtime environment those versions use", and that the code was hardened in 7.2.0. Score: CVSS 4.0 8.7, or 9.4 when chained (DIVD scoring).
- CVE-2026-102490: privilege escalation from the zammad user to root (CWE-269). DIVD says it affects versions 1.5.0 up to the 7.1.0 alpha. On October 1, 2026, Zammad said it had now received the technical details from DIVD and was "working on it". It added that the flaw "cannot be exploited remotely on its own", because an attacker first needs access to the server. No fixed release has been announced. Score: CVSS 4.0 8.5, or 9.4 when chained.
- CISA added both to its Known Exploited Vulnerabilities (KEV) catalogue on October 2, 2026. US federal agencies must act by October 5, 2026, and the entries are flagged for forensic triage.
Checklist:
- Find every Zammad instance, including test, staging and old servers. Note its version and whether it is reachable from the internet.
- Anything on 6.5 or older: treat it as urgent. These versions are no longer supported, according to Zammad. Upgrade to 7.2.0 (released September 23, 2026) or take the instance offline, as DIVD recommends.
- Before you upgrade or rebuild, keep your evidence. Save the application and system logs first. DIVD publishes a log-check script for indicators of compromise linked to CVE-2026-102489, explained in case DIVD-2026-00015. Review any script before you run it.
- On 7.x, upgrade to 7.2.0 anyway, as Zammad advises, and watch Zammad's GitHub security advisories for a fix to CVE-2026-102490.
- Shrink the blast radius until that fix ships. Do not leave the helpdesk open to the whole internet if staff can reach it through a VPN or single sign-on gateway. Restrict outbound traffic from the helpdesk server. Make sure nothing else on that host is reachable or worth stealing.
- If you find signs of compromise, assume root access. Rotate every credential stored on the server or reachable from it, including email connector passwords, API tokens and database credentials, and rebuild rather than clean up.
- Helpdesk staff awareness: DIVD's volunteer contact details leaked. Treat unexpected messages claiming to come from DIVD with care. DIVD asks people to verify them via communications@divd.nl.
Neither DIVD nor Zammad has published network indicators (IP addresses or domains). We are not aware of any official list.
The expert view
What is confirmed and what is not. DIVD's evidence for AI involvement is behavioural. The attack showed machine-speed decisions, scripts carrying the agent's own justifications in natural language, and what DIVD calls sloppy logic. Sysdig's summary of DIVD's findings adds one example: the agent disrupted its own adversary-in-the-middle interception by password spraying at the same time.
That is a reasonable reading, but it is an inference, not proof. DIVD itself separates facts from assumptions in its case file. Three things are still unknown:
- Who sent the agent. DIVD found no link to known public threat actors.
- Whether the agent discovered the zero-days itself or was handed them. Nothing published so far answers this.
- Whether DIVD was a chosen target or one of many.
Why it matters anyway. The pattern matches what threat-intelligence teams have described over the past months: LLM-driven tooling that is noisy and makes errors but is fast enough that "detect and respond" windows shrink to minutes. The rough edges did not save DIVD; segmentation did. The speed also undermines a common habit, patching internet-facing tools on a monthly cycle. When exploitation is automated, the gap between public disclosure and mass exploitation gets shorter.
Why a helpdesk is a good target. A ticketing system receives untrusted input all day from anyone who can send an email. It often stores mailbox credentials and integration tokens, and it is frequently exposed to the internet so customers can reach it. A root shell on that box is a strong foothold.
The chain is the point. Neither flaw alone is a disaster. One gives a low-privilege service account and the other needs local access. Chained, they score 9.4. Defenders often deprioritise "local only" privilege escalation bugs. This case shows why that is risky for any internet-facing application: the remote bug supplies the "local" access.
The disclosure friction is worth noting calmly. Zammad says a CVE identifier was published for a vulnerability it had not been told about, and that it received details of CVE-2026-102490 only on October 1. DIVD's timeline says it reported to Zammad on September 24. For administrators the practical effect is the same either way: a known-exploited root escalation with no released patch, for now. Compensating controls (exposure, egress filtering, monitoring) carry the load until the fix arrives.
What to watch: a Zammad advisory and fixed release for CVE-2026-102490; DIVD's final forensic report, especially on how the agent found the flaws; and whether other victims surface from DIVD's scanning and notification effort.
Official sources
- DIVD — Case DIVD-2026-00014: "When, not if…" (incident and timeline)
- DIVD — Case DIVD-2026-00015: Zammad vulnerabilities and log-check script
- DIVD — CVE-2026-102489 and CVE-2026-102490 records
- Zammad — Staff statements on the DIVD vulnerability reports (October 1, 2026)
- Zammad — Release notes and GitHub security advisories
- CISA — Known Exploited Vulnerabilities catalogue (both CVEs added October 2, 2026)
- Coverage: Sysdig — what we know and how to detect it
- Coverage: Help Net Security
- Coverage: Security Affairs on the KEV addition