Zammad zero-days used to breach bug-disclosure group DIVD

Published

Two previously unknown flaws in Zammad, the open-source helpdesk and ticketing system, were used to break into the Dutch Institute for Vulnerability Disclosure (DIVD), the volunteer group that spends its days warning other organizations about exactly this kind of bug. CISA added both flaws to its Known Exploited Vulnerabilities catalog on 2 October, and DIVD's own investigation says the intrusion was run by an AI agent.

The bugs are CVE-2026-102489 and CVE-2026-102490. DIVD, which assigned both CVE IDs, describes the first as a session hijack vulnerability that leads to remote code execution as the zammad service user, and the second as a privilege escalation that lets that local zammad user become root. Chained, they handed the attackers the server, and DIVD says the agent got from one to the other in seconds.

A helpdesk server became the way in

According to DIVD's incident case file, the attackers first got in on 21 September. DIVD spotted the activity a day later, blocked access to every system in its datacenter, and began a forensic investigation with Merlon Security. It reported the incident to the Dutch data protection authority (Autoriteit Persoonsgegevens) and to NCSC-NL, and discussed its options with the police.

From the Zammad server the attackers reached other services and exfiltrated data before network segmentation and DIVD's response team stopped them going deeper. DIVD has confirmed that volunteer data got out, including DIVD email addresses and possibly contact details, and warns that this makes it easier for someone to pose as a DIVD volunteer. DIVD says it sees no link to any known public threat actor.

Why DIVD thinks an AI agent did it

DIVD calls the modus operandi an agentic AI powered attack, something it says it had not seen before. Its evidence sits in the attacker's own scripts: they carry notes in which the agent justifies its actions and explains why what it is doing is acceptable and not phishing, which DIVD argues a human operator would not bother writing. DIVD describes the attack as loud and messy, with the agent choosing each next step itself at speed, and says its over-explaining comments made reverse engineering easier.

DIVD has shared two redacted log screenshots but says it cannot publish more without hindering the investigation, so the AI attribution is DIVD's assessment rather than something outsiders can yet verify. It does fit a pattern IntelFusions has tracked for weeks, from AI agents compromising 395 organizations via PaperCut to an agent-driven intrusion that took under 10 hours.

Which Zammad versions are exposed

DIVD's vulnerability case file lists:

CISA gave US federal civilian agencies until 5 October to act, three days after the listing.

Upgrade to Zammad 7, or take it offline

DIVD's advice to Zammad operators is blunt: upgrade to version 7, or take the instance offline. Upgrading closes the remote entry point DIVD saw abused, but it should not be read as a complete fix for the second flaw, which DIVD lists as affecting every release through the latest alpha. DIVD says Zammad is working on a fix, so watch the vendor's release notes.

DIVD has also published a log check script, linked from the case file, that searches Zammad logfiles for indicators of compromise from this case. Since 26 September it has been scanning for internet-exposed vulnerable Zammad instances and notifying their owners. Given the stolen volunteer data, verify any unexpected message from a supposed DIVD volunteer directly with DIVD.

The uncomfortable lesson is that a group which hunts exposed systems for a living was caught through its own helpdesk, by an attacker that, on DIVD's account, may not have needed a human at the keyboard.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions