AI agent chained two zero-days to root DIVD in seconds
On September 21 an AI agent breached the Dutch Institute for Vulnerability Disclosure, chaining a Zammad session fixation bug (CVE-2026-102489, CVSS 9.4 chained) with a local privilege escalation (CVE-2026-102490, CVSS 8.5). CISA added the first flaw to its KEV catalog with an October 5 federal deadline; DIVD advises upgrading to Zammad 7 or taking it offline.
- CVE-2026-102489 is exploitable on Zammad 6.3.0–6.5.4, CVSS 9.4 chained
- CVE-2026-102490 affects all versions from 1.5.0 to 7.1.0-alpha
- DIVD detected the intrusion on September 22 and cut off its datacenter
- CISA added the CVE to KEV with an October 5 deadline
Read next
Security