DIVD: Zammad zero-days let AI agent breach its network
The Dutch Institute for Vulnerability Disclosure (DIVD) said its network was breached via a chain of two zero-days in the open-source Zammad ticketing system, tracked as CVE-2026-102489 and CVE-2026-102490. The flaws enabled session hijacking, remote code execution and escalation to root, with an autonomous AI agent carrying out the attack in seconds. DIVD urges Zammad users to upgrade to version 7 or take instances offline.
- Two Zammad zero-days: CVE-2026-102489 and CVE-2026-102490
- Chain enabled session hijacking, RCE and root in seconds
- An autonomous AI agent drove the attack without direction
- DIVD advises upgrading to Zammad 7 or going offline
Read next
Security