Zammad logo

Update: We now know how the AI agent broke into DIVD. On September 30, 2026 at 15:49 (UTC-4), the Dutch Institute for Vulnerability Disclosure revealed that its network was compromised through a chain of two zero-day vulnerabilities in Zammad, the open-source helpdesk and ticketing system. The flaws — now tracked as CVE-2026-102489 and CVE-2026-102490 — enabled session hijacking, remote code execution, and privilege escalation from the Zammad user to root. All of it happened in seconds, thanks to the AI agent driving the attack.

What the zero-days do

Used together, the two vulnerabilities create a complete compromise chain:

  1. CVE-2026-102489 enables session hijacking, allowing the attacker to take over an authenticated user's session without credentials.
  2. CVE-2026-102490 enables remote code execution on the Zammad server.

Once both are chained, the attacker escalates from the low-privilege Zammad service account to root on the host. From there, they can access other services on the same network segment, read data, and exfiltrate it.

"Used together, they allowed the attackers to hijack sessions, run code remotely, and escalate privileges from the Zammad user to root, in seconds, due to the agentic part of this hack," DIVD said in its disclosure.

The AI agent left behind detailed explanations of its own decisions — a forensic gift that let DIVD reconstruct the entire attack chain. This is the same "loud and very, very messy" tradecraft DIVD described earlier: the agent was fast but sloppy, commenting on its own reasoning as it moved through the network.

Why Zammad matters

Zammad isn't a niche tool. It's an open-source, AI-powered helpdesk and support ticketing platform with over 2,000 customers and 55,000 users, including De'Longhi, Amnesty International, and NextCloud. It's available as both self-hosted and hosted SaaS, which means the zero-day chain potentially exposes thousands of organizations — not just DIVD.

DIVD discovered the vulnerabilities in collaboration with Merlon Security and has notified Zammad. The nonprofit is actively alerting other users of vulnerable instances. Its recommendation is blunt: upgrade to Zammad version 7, which is considered safe, or take the instance offline immediately.

Network segmentation at DIVD prevented the attacker from moving deeper into the network after compromising the Zammad host. The investigation is still underway, and DIVD has promised additional updates on October 1, 2026 (UTC).

Why it matters

This update transforms the DIVD breach from a curiosity about AI agent tradecraft into a concrete supply-chain risk for thousands of organizations. The attack vector isn't some exotic AI lab infrastructure — it's a helpdesk ticket system, the kind of tool every mid-sized company runs. If an AI agent can go from a Zammad login page to root in seconds, the perimeter assumption that "our ticket system is low risk" is dead.

The speed is the part that should keep security teams awake. Traditional detection and response operates on a timeline of minutes to hours — an analyst sees an alert, triages it, escalates. An AI agent completes the full kill chain in seconds. Network segmentation was the only control that worked here, and it worked by accident of architecture, not by design. If DIVD's Zammad host had shared a flat network with its core systems, the outcome could have been catastrophic.

There's a critical open question about responsible disclosure timing. DIVD disclosed the CVE numbers and the attack details while presumably other vulnerable Zammad instances remain unpatched. The organization says it's alerting users directly, but with 55,000 users across self-hosted deployments, there will be a window where the vulnerability is public knowledge and patches aren't applied. That window is exactly when copycat attacks — possibly also AI-driven — are most likely.

The Zammad case also highlights a growing tension in open-source security. Zammad bills itself as "AI-powered," and the same AI capabilities that make it a modern helpdesk may have expanded its attack surface. As more infrastructure tools embed AI features, the line between "the AI is a feature" and "the AI is an attack vector" blurs. DIVD's breach is the first documented case where an AI agent exploited an AI-powered tool — a recursive pattern we'll likely see more of.

Watch three things next: whether other Zammad users report compromises from the same zero-day chain in the coming days; how quickly the 2,000+ customers upgrade to version 7; and what DIVD's October 1 update reveals about the attacker's identity, data exfiltrated, and whether other systems were affected. The DIVD breach stopped at the Zammad host this time. The next organization might not be so well-segmented.