SecurityWeek

Zammad Zero-Days Exploited in AI-Powered DIVD Hack


The Dutch Institute for Vulnerability Disclosure (DIVD) was hacked in an automated AI attack that exploited two zero-day vulnerabilities in the web-based, open source user support/ticketing solution Zammad.

The attack occurred on September 21, triggering full incident response, including blocked access to the DIVD infrastructure. The organization immediately started investigating the incident and notified the relevant Dutch authorities.

“This is an attack we have not seen before. Not because it’s our first, but because the modus operandi indicates that this is an agentic AI-powered attack,” it said in a September 24 post on LinkedIn.

DIVD’s investigation identified two zero-day vulnerabilities in Zammad that were exploited for initial access, the organization said on September 30.

The first flaw, CVE-2026-102489 (CVSS score of 9.4), enables unauthenticated attackers to achieve remote code execution and leak user sessions.

The second, CVE-2026-102490 (CVSS score of 9.4), allows a local user to elevate their privileges to root.

Advertisement. Scroll to continue reading.

“Used together, they allowed the attackers to hijack sessions, run code remotely, and escalate privileges from the Zammad user to root, in seconds, due to the agentic part of this hack,” DIVD says.

As part of the attack, the hackers pivoted from the Zammad instance to other services and exfiltrated data, but network segmentation prevented them from going deeper into the environment.

“We’ve found signs of compromise that we’re still looking into, and, until we can prove otherwise, we assume breach. Still, stopping the attackers is a win, and in a situation like this you take every win you can get,” DIVD notes.

After identifying the exploited zero-days, the organization reported them to Zammad, which has been working on a fix.

According to DIVD, Zammad versions 6.3.0 to 6.5.4 are affected. Versions 7.0.0 to 7.1.3 also contain the security defect, but exploitation is not possible due to environment conditions.

“We advise all users of Zammad to upgrade to version 7 of Zammad or to take it offline,” DIVD notes in an advisory.

The institute has published a verification script to help organizations hunt for indicators of compromise (IoCs) and is actively scanning for vulnerable Zammad instances and alerting their owners.

Related: Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability

Related: WatchGuard Patches Critical Fireware OS Code Injection Vulnerability

Related: Chrome, Firefox Updates Patch Over 100 Vulnerabilities

Related: High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL



Source link