DIVD breached for the first time in an attack that looks agentic
The Dutch Institute for Vulnerability Disclosure, which normally finds flaws for others, was itself breached on September 21 via two zero-days in its Zammad helpdesk (CVE-2026-102489 and CVE-2026-102490), reaching root in seconds. DIVD calls the attack "loud and very, very messy" and suspects an autonomous AI agent; CISA added both flaws to its exploited-vulnerabilities catalog.
- CVE-2026-102489 is a session fixation flaw in Zammad 6.3.0–6.5.4 leading to RCE
- CVE-2026-102490 escalates from the zammad account to root in versions 1.5.0–7.1.0-alpha
- CISA added both flaws to its KEV catalog with an October 5 deadline
- DIVD advises upgrading to Zammad 7 or taking instances offline
Read next
Security