Zammad Zero-Days Exploited in AI-Powered DIVD Hack
The Dutch Institute for Vulnerability Disclosure (DIVD) fell victim to an automated, agentic AI-powered attack that exploited two zero-day vulnerabilities in the open-source ticketing platform Zammad.

Incident Overview and Detection
The Dutch Institute for Vulnerability Disclosure (DIVD) experienced a sophisticated security breach on September 21. The incident triggered an immediate full incident response, which included blocking external access to the organization's infrastructure. DIVD promptly launched an internal investigation and notified the relevant Dutch authorities regarding the breach.
Describing the unique nature of the security event, the organization noted in a <a href="https://www.linkedin.com/posts/security-people-always-say-its-not-a-matter-share-7508986128520261632-bafs/">post</a> that the incident utilized methods previously unseen by their team. According to updates shared via <a href="https://www.securityweek.com/zammad-zero-days-exploited-in-ai-powered-divd-hack/">SecurityWeek</a>, the modus operandi pointed directly to an agentic AI-powered attack that operated with rapid execution speeds.
Technical Details of the Zero-Day Vulnerabilities
Subsequent technical analysis revealed that the hackers leveraged two critical zero-day flaws residing within Zammad, a web-based open-source user support and ticketing solution. These vulnerabilities formed the initial access vector utilized during the automated intrusion.
The first security flaw, tracked as CVE-2026-102489, carries a severe CVSS score of 9.4. This vulnerability permits unauthenticated attackers to execute remote code and leak active user sessions. The second flaw, designated as CVE-2026-102490, also carries a CVSS score of 9.4 and enables local users to elevate their privileges all the way to root.
When combined, these two zero-days allowed the malicious actors to hijack sessions, execute remote commands, and escalate permissions from a standard Zammad user account to root in mere seconds. DIVD attributed this rapid execution timeline directly to the agentic AI capabilities driving the attack.
Lateral Movement and Data Exfiltration
During the sequence of events, the malicious agents successfully pivoted from the compromised Zammad instance to other internal services. The attackers managed to exfiltrate data from the environment before further containment actions took effect.
Despite the successful lateral movement, rigid network segmentation played a vital role in blunting the full impact of the intrusion. DIVD noted that network boundaries successfully prevented the attackers from moving deeper into the core infrastructure, limiting the overall breadth of the breach.
DIVD stated that while signs of compromise continue to be analyzed, the organization operates under a confirmed breach assumption until proven otherwise. Even with ongoing remediation tasks, stopping the active threat actors was characterized as a major tactical victory.
Mitigation and Response Measures
Following the discovery of the vulnerabilities, DIVD reported the zero-day flaws to the Zammad development team, which immediately began working on appropriate patches and fixes. Affected software builds include Zammad versions 6.3.0 through 6.5.4. While versions 7.0.0 to 7.1.3 also contain the security defect, exploitation remains blocked due to specific environment conditions.
To address the threat landscape, DIVD published a formal <a href="https://csirt.divd.nl/cases/DIVD-2026-00015/">advisory</a> recommending that all active Zammad users immediately upgrade to version 7 or alternatively take their deployments offline until updates can be properly applied.
Additionally, the institute released a dedicated verification script to assist system administrators in hunting for indicators of compromise. DIVD teams are also actively scanning for vulnerable Zammad instances across the wider web to alert respective owners of their exposure.
Sources
- SecurityWeekZammad Zero-Days Exploited in AI-Powered DIVD Hack