The Dutch Institute for Vulnerability Disclosure (DIVD), a cybersecurity non-profit, recently disclosed that it was compromised in an attack that exploited two zero-day vulnerabilities in its Zammad helpdesk platform. The incident, detected on September 24, involved the use of what DIVD describes as an "agentic AI" to execute the attack.
The vulnerabilities, identified as CVE-2026-102489 (remote code execution) and CVE-2026-102490 (elevation of privileges), were chained together. When exploited in combination, they achieved a CVSS score of 9.4. DIVD stated that these flaws allowed attackers to hijack sessions, execute remote code, and escalate privileges from the Zammad user to root within seconds.
Following the initial compromise, the attackers were able to access other services and exfiltrate data. DIVD confirmed that volunteer data, including DIVD email addresses and potentially contact details, was compromised. This raises concerns about potential impersonation attempts targeting DIVD staff.
DIVD urged all users of Zammad to update to version 7 immediately or take their systems offline if an update is not possible.
The organization's internal investigation indicated that artificial intelligence played a role in the attack. DIVD reported that logs contained notes within the attacker's scripts where the AI agent justified its actions, explaining why its activities were permissible and not phishing. This behavior, according to DIVD, is atypical for human attackers and supports their assessment of an agentic AI-powered attack. Further details are being withheld to avoid interfering with the ongoing investigation.
Despite the breach, DIVD's security measures helped limit the damage. The organization credited proper network segmentation and the swift actions of its IT and incident response teams for preventing the attackers from penetrating deeper into their systems and network. This containment strategy was crucial in mitigating the overall impact of the compromise.






