[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fb0rgebhKrkZOOYE78bs6KB1LG89Ewm_z6ak_-R09MVY":3},{"article":4,"iocs":48},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":27,"category":28,"article_tags":32},"3e6e3d96-2311-41a7-92b2-04b09d2d9642","Zammad Zero-Days Exploited in AI-Powered DIVD Hack","zammad-zero-days-exploited-in-ai-powered-divd-hack-c06bed","The flaws were chained to hijack sessions, achieve remote code execution, and elevate privileges to root. The post Zammad Zero-Days Exploited in AI-Powered DIVD Hack appeared first on SecurityWeek.","The Dutch Institute for Vulnerability Disclosure (DIVD) was compromised on September 21 via an AI-powered automated attack exploiting two zero-day vulnerabilities in Zammad, an open-source ticketing system. The flaws (CVE-2026-102489 and CVE-2026-102490, both CVSS 9.4) allowed attackers to achieve remote code execution, hijack sessions, and escalate privileges to root. Network segmentation contained the breach, though data exfiltration occurred and compromise is assumed pending further investigation.","DIVD hacked via two Zammad zero-days exploited in AI-powered automated attack.","The Dutch Institute for Vulnerability Disclosure (DIVD) was hacked in an automated AI attack that exploited two zero-day vulnerabilities in the web-based, open source user support\u002Fticketing solution Zammad. The attack occurred on September 21, triggering full incident response, including blocked access to the DIVD infrastructure. The organization immediately started investigating the incident and notified the relevant Dutch authorities. “This is an attack we have not seen before. Not because it’s our first, but because the modus operandi indicates that this is an agentic AI-powered attack,” it said in a September 24 post on LinkedIn. DIVD’s investigation identified two zero-day vulnerabilities in Zammad that were exploited for initial access, the organization said on September 30. The first flaw, CVE-2026-102489 (CVSS score of 9.4), enables unauthenticated attackers to achieve remote code execution and leak user sessions. The second, CVE-2026-102490 (CVSS score of 9.4), allows a local user to elevate their privileges to root.Advertisement. Scroll to continue reading. “Used together, they allowed the attackers to hijack sessions, run code remotely, and escalate privileges from the Zammad user to root, in seconds, due to the agentic part of this hack,” DIVD says. As part of the attack, the hackers pivoted from the Zammad instance to other services and exfiltrated data, but network segmentation prevented them from going deeper into the environment. “We’ve found signs of compromise that we’re still looking into, and, until we can prove otherwise, we assume breach. Still, stopping the attackers is a win, and in a situation like this you take every win you can get,” DIVD notes. After identifying the exploited zero-days, the organization reported them to Zammad, which has been working on a fix. According to DIVD, Zammad versions 6.3.0 to 6.5.4 are affected. Versions 7.0.0 to 7.1.3 also contain the security defect, but exploitation is not possible due to environment conditions. “We advise all users of Zammad to upgrade to version 7 of Zammad or to take it offline,” DIVD notes in an advisory. The institute has published a verification script to help organizations hunt for indicators of compromise (IoCs) and is actively scanning for vulnerable Zammad instances and alerting their owners. Related: Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability Related: WatchGuard Patches Critical Fireware OS Code Injection Vulnerability Related: Chrome, Firefox Updates Patch Over 100 Vulnerabilities Related: High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Chrome, Firefox Updates Patch Over 100 VulnerabilitiesRussian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent AttacksShinyHunters Defiant After FBI Calls on Members to Come ForwardReco Raises $55 Million for Agentic SecurityHackers Use ChatGPT Custom GPTs in ClickFix AttacksDutch Police Arrest Convicted Hacker in ShinyHunters InvestigationDaemon Tools Hackers’ NeedyMantis Malware Dissected by MicrosoftPrison Sentence for Former US Soldier Who Hacked AT&T and Verizon Latest News Kevin Mandia’s Armadin Raises $255 Million at $2.5 Billion ValuationTreasury Blacklists Most-Wanted ATM Malware Developer and His Network500,000 Active Credentials Left Exposed on GitHubCisco Patches Exploited Catalyst SD-WAN Zero-Day VulnerabilityGoogle Launches Gemini 4 Argon With Guardrail-Free Access for Vetted DefendersFTC is Investigating OpenAI and Anthropic Over Possible Risks to ConsumersGoogle: AI Is Changing the Pace and Profile of Vulnerability DiscoveryWatchGuard Patches Critical Fireware OS Code Injection Vulnerability Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveQuantum Secure Encryption Corp. has appointed Joseph Hall as CIO.David Cass has joined Grayscale Investments as Chief Risk Officer.Thomas Dager has been appointed Vice President and Chief Information Security Officer at The Goodyear Tire & Rubber Company.More People On The MoveExpert Insights Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fzammad-zero-days-exploited-in-ai-powered-divd-hack\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2023\u002F06\u002Fzero-day-e1772721069481.jpg","2026-10-01T10:42:49+00:00","2026-10-01T12:00:19.249389+00:00",9,[18,21,24],{"name":19,"type":20},"DIVD (Dutch Institute for Vulnerability Disclosure)","vendor",{"name":22,"type":23},"Zammad","product",{"name":25,"type":26},"AI-powered agentic attack automation","technology","574f766a-fb3f-487c-8d2c-0720ae75471b",{"id":27,"icon":29,"name":30,"slug":31},null,"Zero-day","zero-day",[33,38,43],{"category":34},{"id":35,"icon":29,"name":36,"slug":37},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":39},{"id":40,"icon":29,"name":41,"slug":42},"839da5c1-3c34-47e2-9499-f7201640e3ac","AI Security","ai-security",{"category":44},{"id":45,"icon":29,"name":46,"slug":47},"ade75414-7914-4e23-a450-48b64546ee70","Open Source","open-source",[49,53],{"type":50,"value":51,"context":52},"cve","CVE-2026-102489","Zammad zero-day enabling unauthenticated RCE and session leak (CVSS 9.4)",{"type":50,"value":54,"context":55},"CVE-2026-102490","Zammad zero-day allowing local privilege escalation to root (CVSS 9.4)"]