DIVD Reveals Zammad Zero-Days Powered AI Network Breach
The Dutch Institute for Vulnerability Disclosure has reported that its network was compromised using a pair of zero-day vulnerabilities in the open-source Zammad ticketing system, exploited by an autonomous AI agent.

Introduction to the Zammad Zero-Day Attack
The Dutch Institute for Vulnerability Disclosure (DIVD) has disclosed critical details regarding a security incident impacting its network infrastructure. According to the volunteer cybersecurity nonprofit, the unauthorized network intrusion was made possible by exploiting a dangerous chain of two zero-day vulnerabilities affecting the open-source Zammad ticketing system. As detailed in coverage by reporting platforms such as BleepingComputer, this sophisticated attack highlights emerging risks involving automated threat execution and enterprise software vulnerabilities. Further details are available from BleepingComputer in the original source material.
Prior to releasing comprehensive technical indicators, the organization described the incident as loud and very messy. What made the intrusion particularly unique was the involvement of an advanced autonomous actor rather than traditional manual operators. Detailed insights into how the event unfolded have been extensively documented by cybersecurity analysts tracking the evolving threat landscape.
Technical Breakdown of the Vulnerabilities
The security flaws exploited during the incident have been officially cataloged as CVE-2026-102489 and CVE-2026-102490. When chained together, these critical software weaknesses granted malicious actors deep access into targeted systems. Specifically, the vulnerabilities enabled session hijacking, remote code execution, and a rapid escalation path from standard application permissions all the way up to root privileges.
DIVD noted that because the entire intrusion was managed through automated systems, the malicious actions occurred at machine speed. Within a matter of seconds following the initial exploit execution, the threat actor gained the ability to read, access, and exfiltrate sensitive data from affected enterprise systems.
Autonomous AI Agent Behavior and Investigation
One of the most notable aspects of the incident was the presence of an autonomous AI agent that determined its own tactical steps without requiring external human intervention or continuous remote direction. Interestingly, this automation left behind extensive operational logs and explanations regarding its decision-making process. These leftover artifacts provided DIVD investigators with a rare window into the internal logic of the autonomous system, enabling a precise reconstruction of the attack vector.
Despite the speed and autonomy of the attack, proactive network defenses prevented total network compromise. Effective network segmentation combined with immediate incident response measures successfully blocked the threat actor from moving deeper into internal segments. However, the organization's formal investigation into the full scope of the breach remains ongoing.
About the Affected Zammad Ecosystem
Zammad is a widely deployed open-source, AI-powered helpdesk and support ticketing solution utilized by organizations globally to manage customer service inquiries, internal IT support tickets, and general communications. The platform is offered as both a self-hosted solution and a fully managed hosted service.
According to official metrics shared by the vendor on its website, the Zammad platform supports an extensive enterprise footprint consisting of more than 2,000 customers and approximately 55,000 individual users. Prominent organizations listed among its customer base include major international entities such as De’Longhi, Amnesty International, and NextCloud.
Mitigation Steps and Industry Response
DIVD discovered the zero-day vulnerabilities in close collaboration with Merlon Security. Following the identification and analysis of the flaws, the nonprofit promptly notified Zammad regarding the security risks and began working to warn other system administrators running vulnerable deployments.
To mitigate active risks, the organization strongly advises all users operating Zammad deployments to upgrade their instances immediately to version 7, which addresses the vulnerabilities and is currently considered safe. For installations that cannot be patched immediately, administrators are urged to take their vulnerable instances offline as quickly as possible to prevent potential exploitation.
Sources
- BleepingComputerDIVD says Zammad zero-days enabled AI-driven network breach