DIVD Warns AI-Driven Attack Exploited Two Zammad Zero-Day Vulnerabilities
The Dutch Vulnerability Disclosure Institute (DIVD) said a network breach was made possible by exploiting two zero-day vulnerabilities in the open-source Zammad ticketing system.
The nonprofit organization, which is made up of volunteer security researchers, previously described the attack as “loud and very, very nasty.” According to DIVD, an AI agent carried out the attack autonomously, deciding its next steps without outside intervention or direction.
Because the AI agent left a detailed explanation of its decisions, DIVD obtained extensive information about the attack and was able to reconstruct the incident.
Two Zammad zero-days enabled session hijacking and root access
According to the cybersecurity nonprofit, the two flaws—currently identified as CVE-2026-102489 and CVE-2026-102490—allowed session hijacking, remote code execution, and root privilege escalation.
After exploiting the vulnerabilities, the attacker was able to access other services and read and steal data from DIVD’s systems. With AI automation, all of these operations were completed within seconds.
“Used in combination, the agent portion of this hack allowed an attacker to hijack sessions, remotely execute code, and escalate privileges from the Zammad user to root in seconds,” DIVD said.
Network segmentation and incident response measures prevented the attacker from penetrating deeper into the network. However, the investigation remains ongoing.
DIVD urges Zammad users to upgrade or take systems offline
Zammad is an open-source, AI-powered helpdesk and support ticketing platform used to manage customer inquiries, IT support requests, and internal tickets.
The platform is available as both a self-hosted and hosted service. According to Zammad’s website, it has more than 2,000 customers and 55,000 users, including De’Longhi, Amnesty International, and NextCloud.
DIVD worked with Merlon Security to discover the zero-day vulnerabilities. The organization notified Zammad about the issues and is warning users about vulnerable instances.
DIVD recommends that Zammad users upgrade to version 7, which it considers secure, or take their instances offline as soon as possible.
The nonprofit said it would share additional updates about the incident tomorrow.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, correct, and revalidate at machine speed.
Source: www.bleepingcomputer.com



