chiprook
← Security
SecurityOctober 4, 2026, 14:30

AI agent chained two zero-days to root DIVD in seconds

On September 21 an AI agent breached the Dutch Institute for Vulnerability Disclosure, chaining a Zammad session fixation bug (CVE-2026-102489, CVSS 9.4 chained) with a local privilege escalation (CVE-2026-102490, CVSS 8.5). CISA added the first flaw to its KEV catalog with an October 5 federal deadline; DIVD advises upgrading to Zammad 7 or taking it offline.

AI agent chained two zero-days to root DIVD in seconds
#Zammad#CISA#DIVD
Read next
Security

SonicWall SMA1000 Command Injection CVE-2026-83549 Chained to Root

Security

CISA adds two Zammad flaws to Known Exploited Vulnerabilities catalog

Security

AI agent swarm compromised 440 PaperCut servers in 26 seconds each

Security

CVE-2026-84411 in MikroTik RouterOS: unauthenticated HTTP request reaches root