Dutch security group DIVD says an AI agent breached it via two Zammad zero‑days
DIVD says an attacker chained two zero-days in open-source helpdesk Zammad to reach root, and that an AI agent decided each step itself.
The Dutch Institute for Vulnerability Disclosure said attackers breached its systems on 21 September using two zero-days in Zammad, the open-source helpdesk platform, according to BleepingComputer and posts on X. One flaw lets a Zammad user run code on the server, and the other escalates to root.
The two flaws have been given the identifiers CVE-2026-102489 and CVE-2026-102490, according to BleepingComputer. DIVD says they allowed session hijacking, remote code execution and privilege escalation. After that, the attacker read and exfiltrated data from other services, DIVD said, in a matter of seconds.
DIVD believes an AI agent carried out the attack. The volunteers called it loud and messy, and said the agent decided its next step after every action and did some pretty dumb things, including disrupting its own password-spraying attempt. That attribution is DIVD's assessment, and nobody has confirmed which model or operator was involved.
The agent left clear explanations of its decisions behind, which let DIVD reconstruct the incident, according to reports. Network segmentation and incident response stopped the attacker moving deeper into the network. DIVD said one flaw affects all Zammad versions, and a full fix was not yet available on Wednesday.
The case matters because the victim is a group that finds and reports vulnerabilities for others. The Zammad project's own response was not included in the reports read for this story, so its patch timeline is unknown.