Skip to content
Unlisted Report logoUnlisted ReportSubscribe
Vulnerabilities

AI agent chains Zammad zero-days to breach DIVD

Attackers used two Zammad helpdesk zero-days and an AI agent to go from user to root in seconds at the Dutch Institute for Vulnerability Disclosure.

By · Published · Updated · 5 min read

Lock image for the Zammad zero-day breach

The Dutch Institute for Vulnerability Disclosure (DIVD) — a volunteer group that finds security holes in other people's software — has revealed it was breached through two zero-days in its own helpdesk system, Security Affairs reports.

What happened

Attackers got in through Zammad, an open-source ticketing platform. With Merlon Security, DIVD found two previously unknown flaws:

  • CVE-2026-102489
  • CVE-2026-102490

Chained together, they let attackers hijack sessions, run code remotely and go from an ordinary Zammad account to root access in seconds. From there, they reached other services and stole data.

The irony is hard to miss. DIVD's entire mission is scanning the internet for vulnerable systems and quietly warning their owners before criminals find them. Its own helpdesk — the system it uses to coordinate those warnings — turned out to be the vulnerable system.

The AI factor

DIVD said the speed of the attack was down to the use of an AI agent. Steps that would take a human attacker minutes or hours — testing, chaining and escalating — happened almost instantly.

This is the part of the incident that should worry defenders most. Security teams have long relied on the assumption that exploiting a fresh vulnerability takes an attacker time: time to understand the flaw, time to write the exploit, time to move through the network. An AI agent compresses all of that into the gap between two log lines. By the time an alert fires, the attacker may already be done.

Why it matters

If an organization of professional vulnerability hunters can be breached this way, anyone can. AI-driven attacks shrink the time defenders have to spot and stop an intrusion from hours to seconds, which breaks the detection-and-response model most security teams are built around.

There is also a supply-chain angle. DIVD holds sensitive information about unpatched vulnerabilities in thousands of organizations. A breach of its systems is not just one organization's problem — it potentially hands attackers a map of everyone else's open wounds. DIVD has not suggested its vulnerability reports were the target, but the possibility alone underlines how much trust is concentrated in disclosure organizations.

What Zammad users should do

DIVD urges everyone running any version of Zammad to:

  1. Update to version 7 immediately, or take the system offline.
  2. Review logs for unusual sessions and new admin accounts.
  3. Rotate passwords and API keys stored in or connected to Zammad.

Helpdesk systems deserve special attention beyond this one incident. They are internet-facing by design, hold credentials and sensitive conversations, and are often connected to email and identity systems — a near-perfect pivot point for an attacker.

Sources

Read next