← All stories
● Covered by 2 sources · 2 reportsMedium impact2 neutral

DIVD Network Breach Linked to Zammad Zero-Days and AI-Driven Attack

🔄 Updated 1d ago — new reporting from SecurityWeek
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • DIVD network breached via Zammad zero-days.
  • AI agent automated attack, exfiltrated data.
  • Vulnerabilities: CVE-2026-102489, CVE-2026-102490.
  • Zammad users advised to upgrade to version 7.
  • Attack occurred on September 21.
  • DIVD blocked access to its infrastructure.
  • DIVD notified Dutch authorities.
  • DIVD posted about the attack on LinkedIn on September 24.
  • DIVD identified vulnerabilities on September 30.
  • CVE-2026-102489 has a CVSS score of 9.4.
  • CVE-2026-102490 has a CVSS score of 9.4.
  • CVE-2026-102489 allows unauthenticated remote code execution and session leakage.
  • CVE-2026-102490 allows local users to elevate privileges to root.

Zammad Zero-Days Exploited in DIVD Breach

The Dutch Institute for Vulnerability Disclosure (DIVD) confirmed that its network was compromised through a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. These vulnerabilities, now designated CVE-2026-102489 and CVE-2026-102490, allowed attackers to hijack sessions, execute remote code, and escalate privileges to root level.

AI Agent Orchestrated Attack

The attack was characterized by an autonomous AI agent that made decisions without external intervention. This agent exploited the Zammad flaws to access other services, read, and exfiltrate data from DIVD's systems within seconds. The AI agent left detailed explanations of its decisions, which aided DIVD in reconstructing the incident.

Impact and Mitigation

The combined exploitation of the zero-days enabled rapid compromise, including session hijacking and privilege escalation. Despite the speed of the attack, network segmentation and incident response measures prevented the threat actor from moving deeper into DIVD's network. The investigation into the incident is ongoing.

Recommendations for Zammad Users

Zammad is an open-source helpdesk platform used by over 2,000 customers. DIVD, in collaboration with Merlon Security, discovered these vulnerabilities and notified Zammad. DIVD recommends that all Zammad users upgrade to version 7, which addresses these issues, or take their instances offline immediately if upgrading is not possible.

Updates

🕒 2026-10-01 · new reporting from SecurityWeek
  • Attack occurred on September 21.
  • DIVD blocked access to its infrastructure.
  • DIVD notified Dutch authorities.
  • DIVD posted about the attack on LinkedIn on September 24.
  • DIVD identified vulnerabilities on September 30.
  • CVE-2026-102489 has a CVSS score of 9.4.
  • CVE-2026-102490 has a CVSS score of 9.4.
  • CVE-2026-102489 allows unauthenticated remote code execution and session leakage.
  • CVE-2026-102490 allows local users to elevate privileges to root.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

The Dutch Institute for Vulnerability Disclosure (DIVD) was hacked through two zero-day vulnerabilities in the Zammad ticketing solution, which DIVD described as an "agentic AI-powered attack." The vulnerabilities allowed remote code execution, session hijacking, and privilege escalation, leading to data exfiltration from the Zammad instance.

The Dutch Institute for Vulnerability Disclosure (DIVD) reported that its network breach was caused by two zero-day vulnerabilities in the Zammad ticketing system, identified as CVE-2026-102489 and CVE-2026-102490. These flaws allowed session hijacking, remote code execution, and root privilege escalation, with an AI agent automating the attack and data exfiltration.