DIVD: AI-driven attackers used two Zammad zero-days to breach its network
The Dutch Institute for Vulnerability Disclosure said its network was breached via a chain of two zero-day flaws in the open-source Zammad ticketing platform, tracked as CVE-2026-102489 and CVE-2026-102490. DIVD said the attack was carried out by an autonomous AI agent that hijacked sessions, executed code remotely, and escalated to root privileges within seconds. Network segmentation and DIVD's response reportedly stopped the attacker from moving further into its systems.
GoKawiil's interpretation of the reporting above, not reported fact.
The incident suggests that AI agents can now chain vulnerabilities and escalate privileges at machine speed, potentially compressing attack timelines that previously took human operators much longer. Because Zammad claims over 2,000 customers including organizations like Amnesty International and NextCloud, unpatched instances could be exposed to similar automated exploitation until they upgrade. DIVD's ability to reconstruct the attack from the AI's own logged reasoning also hints that such agents may leave distinctive forensic trails, which could aid future detection.
- Two Zammad zero-days (CVE-2026-102489, CVE-2026-102490) enabled session hijacking, remote code execution, and root escalation.
- DIVD says an autonomous AI agent executed the full attack chain in seconds without human direction.
- DIVD recommends Zammad users upgrade to version 7 and is notifying other potentially affected users.
Source: bleepingcomputer.com, 2026-09-30
Published there as: “DIVD says Zammad zero-days enabled AI-driven network breach”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.