Did an AI Agent Hack DIVD? The Zammad Zero-Days
Summary
The Dutch Institute for Vulnerability Disclosure (DIVD) says it was breached on September 21 by an automated attacker that behaved like an agent, choosing its next steps during the intrusion. The institute detected the incident on September 22 and disclosed it publicly on September 24, while still treating the case as an open breach investigation. The attacker combined password spraying with an attempt to sit between two systems and read traffic, and left detailed comments that helped investigators reconstruct its activity. DIVD has not identified the model, operator, or full scope of the incident. The intrusion used two previously unknown Zammad vulnerabilities, CVE-2026-102489 and CVE-2026-102490. The first could hijack a session and enable remote code execution as the zammad user in affected 6.3.0-6.5.4 releases; DIVD says the same flaw in 7.0.0-7.1.3 was not exploitable because of the environment. The second vulnerability allowed that local user to become root and was present across the versions DIVD checked, including v7.1.0-alpha. Used together, the flaws reportedly took the attacker from a hijacked session to root within seconds and enabled access to other services and data. Network segmentation and DIVD’s incident response prevented deeper movement, but the institute has not published what data was taken. DIVD notified Dutch authorities and police on September 24, began scanning for exposed Zammad systems on September 26, and credited Merlon Security researchers with finding the flaws. It advises Zammad operators to upgrade to version 7 or take the software offline, and has released a log-checking script for signs of the session hijack.