The Dutch Institute for Vulnerability Disclosure exists to find flaws in other people’s software. This time it found two in its own helpdesk, after an AI-driven intruder used them to seize the machine.
DIVD was breached on September 21 and went public this week. The entry point was Zammad, an open-source ticketing platform the nonprofit ran internally. Working with Merlon Security, DIVD identified two zero-days, tracked as CVE-2026-102489 and CVE-2026-102490. Both carry a CVSS score of 9.4.
The first allows unauthenticated attackers to run code remotely and leak user sessions. The second lets a local user escalate to root. Chained together, they let the intruder hijack sessions and climb from an ordinary Zammad account to root in seconds.
“This is an attack we have not seen before,” DIVD wrote. The organization attributes the speed and autonomy to an agentic AI tool making decisions without a human operator.
Once inside, the attacker pivoted to other services and exfiltrated data, but network segmentation and a fast incident response stopped deeper movement. Versions 6.3.0 through 6.5.4 are affected; 7.0.0 to 7.1.3 carry the defect but cannot be exploited. DIVD urges every Zammad user to upgrade to version 7 or take it offline, and has published a script to hunt for indicators of compromise.
