VYPR
breachPublished Oct 1, 2026· 1 source

Zammad Zero-Days Exploited in AI-Powered Attack on DIVD

The Dutch Institute for Vulnerability Disclosure (DIVD) was targeted by an AI-powered attack exploiting two zero-day vulnerabilities in the Zammad customer support platform, leading to a breach of DIVD's own infrastructure.

The Dutch Institute for Vulnerability Disclosure (DIVD) has fallen victim to a sophisticated, AI-driven cyberattack that leveraged two previously unknown vulnerabilities in the Zammad customer support platform. The incident, which occurred on September 21st, forced DIVD to initiate a full incident response and temporarily block access to its infrastructure. This attack marks a significant escalation, with DIVD noting the "agentic AI-powered attack" as a novel modus operandi.

DIVD's investigation revealed that the attackers exploited two zero-day vulnerabilities in Zammad, a popular open-source web-based ticketing and user support solution. The first flaw, identified as CVE-2026-102489 with a CVSS score of 9.4, allowed unauthenticated attackers to achieve remote code execution and leak user sessions. The second vulnerability, CVE-2026-102490, also rated at 9.4, permitted a local user to escalate their privileges to root access.

When chained together, these vulnerabilities provided a rapid pathway for attackers. DIVD stated that the combined exploit allowed attackers to hijack sessions, execute remote code, and escalate privileges from a Zammad user to root within seconds, facilitated by the "agentic" nature of the AI. This automation and speed are key characteristics of the observed attack.

Following the initial compromise of the Zammad instance, the attackers successfully pivoted to other services within DIVD's environment and exfiltrated data. Fortunately, network segmentation measures prevented the attackers from penetrating deeper into DIVD's network, limiting the overall scope of the breach. Despite this, DIVD is treating the incident with utmost seriousness, assuming a full breach until proven otherwise.

Upon discovering the exploited zero-days, DIVD promptly reported the vulnerabilities to Zammad, which has since been working on developing and releasing patches. According to DIVD's advisory, Zammad versions 6.3.0 through 6.5.4 are affected, as are versions 7.0.0 through 7.1.3, although exploitation in the latter is reportedly not possible due to environmental conditions.

DIVD strongly advises all Zammad users to upgrade to version 7 of the platform or, as an interim measure, to take affected instances offline. To aid organizations in detecting potential compromises, DIVD has released a verification script and is actively scanning for vulnerable Zammad instances, alerting their owners to the risks.

The incident highlights the growing threat of AI-powered attacks, which can automate reconnaissance, exploitation, and lateral movement with unprecedented speed and efficiency. The use of AI in cyberattacks poses a significant challenge to traditional security defenses, necessitating more advanced detection and response capabilities.

This event underscores the critical importance of timely patching and vulnerability management, especially for widely used software like Zammad. The exploitation of zero-days, particularly when combined with AI-driven automation, presents a potent threat that requires continuous vigilance and rapid response from both vendors and users.

Synthesized by Vypr AI