The Dutch Institute for Vulnerability Disclosure (DIVD), a non-profit organization that identifies and reports software vulnerabilities, confirmed it was breached on September 21 through the exploitation of two zero-day vulnerabilities in Zammad, an open-source helpdesk and customer support ticketing system. The attack was attributed to an "agentic AI" system, which reportedly used the flaws to achieve remote code execution and privilege escalation from a Zammad user to root access within seconds.
The DIVD stated that the AI agent's actions were "loud and very very messy," exhibiting automated decision-making at high speed, sometimes with "sloppy logic." Despite this, the organization noted that the agent's "overexplaining" comments within its operations were aiding their reverse engineering efforts. The incident has been reported to the Autoriteit Persoonsgegevens (Dutch Data Protection Authority), the Dutch National Cyber Security Centre (NCSC-NL), and discussed with law enforcement.
The two exploited vulnerabilities are CVE-2026-102489 and CVE-2026-102490. CVE-2026-102489 allows unauthenticated attackers to execute arbitrary code remotely and affects Zammad versions 6.3.0 through 6.5.4. While this specific vulnerability is not exploitable in Zammad versions 7.0.0 through 7.1.3 due to environmental factors, it remains a concern for older installations. CVE-2026-102490 is a privilege escalation flaw that enables authenticated low-privilege users to gain root access on the system. This vulnerability impacts all Zammad versions, including the latest alpha release.
DIVD, with assistance from Merlon Security researchers, identified the zero-days and promptly notified Zammad GmbH, which is now developing patches. In the interim, DIVD has begun identifying internet-exposed vulnerable Zammad instances and notifying their administrators.
While the full scope of data accessed by the AI agents is still under investigation, DIVD confirmed that network segmentation and rapid response by its IT and incident response teams limited the compromise. The organization stated, "We were able to stop the attackers from going deeper into our systems and network. Unfortunately some of the damage was already done."
Zammad users are strongly advised to upgrade to Zammad version 7 or take their systems offline if an upgrade is not immediately possible. For those wishing to investigate potential compromise, DIVD has released a log check script to scan Zammad log files for indicators of compromise. The NCSC-NL recommends making copies of application and network logs before applying any updates, as these logs could be crucial for future investigations into the second vulnerability's exploitation. The motivation behind the attack, whether it was part of a larger cyber operation or a capability test, remains unknown.






