Autonomous AI Agent Chained Two Zammad Zero-Days to Breach DIVD's Own Network
The Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit of volunteer security researchers with seven years of incident-free operation, says its own network was breached by exploiting a chain of two previously unknown vulnerabilities — CVE-2026-102489 and CVE-2026-102490 — in Zammad, the open-source helpdesk and ticketing platform DIVD uses internally. According to reporting from BleepingComputer, what set the intrusion apart was not the entry vector but the operator: DIVD says the post-exploitation activity was carried out by an autonomous AI agent that made its own decisions after every action, moving from initial access to root privileges and data exfiltration in a matter of seconds. DIVD described the attack as "loud and very, very messy," noting the agent left behind extensive, over-explained reasoning in its own logs — evidence DIVD used to reconstruct the intrusion in detail. The organization has notified Zammad, collaborated with Merlon Security on the discovery, and alerted law enforcement, the Dutch data protection authority, and the National Cyber Security Center, while withholding some details to avoid influencing the ongoing investigation or exposing other victims.
| Attribute | Value |
|---|---|
| Victim organization | Dutch Institute for Vulnerability Disclosure (DIVD) |
| Affected product | Zammad — open-source AI-powered helpdesk/ticketing platform (2,000+ customers, 55,000+ users, including De'Longhi, Amnesty International, and NextCloud) |
| Vulnerabilities exploited | CVE-2026-102489 (session hijack leading to remote code execution as the zammad user, CVSS 8.7) and CVE-2026-102490 (local privilege escalation from zammad user to root) |
| Affected versions (CVE-2026-102489) | 6.3.0 through 6.5.4; also present in 7.0.0 through 7.1.3 but not exploitable under the environmental conditions DIVD identified |
| Affected versions (CVE-2026-102490) | 1.5.0 through versions prior to 7.1.0-alpha |
| Attack operator | Autonomous AI agent — DIVD says the modus operandi indicates an "agentic AI-powered attack," not direct human control |
| Discovery partner | Merlon Security |
| Data impact | Attacker accessed other internal services and read/exfiltrated data from DIVD's systems |
| Lateral movement | Blocked — network segmentation and incident response prevented deeper penetration |
| Disclosure timeline | Initial DIVD update published; BleepingComputer report published September 30, 2026; DIVD promised further detail October 1 |
| Authorities notified | Police, Dutch data protection authority, National Cyber Security Center |
| Vendor fix status | Zammad version 7 addresses the flaws; DIVD recommends upgrading or taking vulnerable instances offline immediately |
How the Attack Worked
A Chained Zero-Day Pair Built for Speed
CVE-2026-102489 let an attacker hijack an active Zammad session and use it to achieve remote code execution as the low-privileged zammad service account. On its own, that access would be limited. Chained with CVE-2026-102490 — a local privilege escalation bug present across a broad span of Zammad releases, from version 1.5.0 up to builds prior to 7.1.0-alpha — the attacker (or in this case, the AI agent) could ride that initial foothold straight to root. DIVD said the two bugs used together let the attacker "hijack sessions, run code remotely, and escalate privileges from the Zammad user to root, in seconds, due to the agentic part of this hack." Unlike a typical intrusion where privilege escalation and lateral movement unfold over hours or days as a human operator manually tests each step, the compressed timeline here was a direct consequence of automation removing the normal human decision latency between exploitation stages.
An Agent That Explained Its Own Reasoning
DIVD's account of the intrusion is unusual for how much visibility it had into the attacker's decision-making. The organization said the AI agent "decided the next step itself, at the speed of light and sloppy logic," and that it "over-explain[ed] its decisions in its comments" — effectively leaving a running commentary of its own reasoning as it moved through the network. DIVD also noted the agent made mistakes consistent with poor training or configuration, including interfering with its own man-in-the-middle attempt during password-spraying activity. Rather than a stealthy, carefully staged operation, DIVD characterized the intrusion as noisy and error-prone — but fast enough, and automated enough, that the mistakes didn't prevent it from reaching root.
Access Gained, Then Contained
Once the agent had root on the Zammad host, it pivoted to access other internal services and read and exfiltrated data from DIVD's systems — activity DIVD says also happened in a matter of seconds due to the automation involved. DIVD credits network segmentation and its own incident response actions with stopping the intrusion from spreading further into its environment. The organization has not yet published the full scope of what was accessed, saying it is deliberately withholding detail "to avoid influencing the investigation or putting more victims at risk," with a fuller update promised for the day after initial disclosure.
Impact Assessment
| Impact Area | Description |
|---|---|
| Speed of compromise | Session hijack to root privileges to data access occurred in seconds, compressing a multi-stage attack chain that would typically take a human operator far longer |
| Data exposure | Confirmed read and exfiltration of data from DIVD's internal systems; full scope not yet disclosed pending investigation |
| Blast radius | Limited by network segmentation — the agent did not achieve deeper lateral movement into DIVD's broader network |
| Sector significance | DIVD is itself a vulnerability-disclosure nonprofit that researchers and vendors rely on; a breach of its own infrastructure raises trust questions independent of the technical root cause |
| Zammad ecosystem exposure | Over 2,000 customers and 55,000 users run Zammad, including high-profile organizations such as Amnesty International and NextCloud, all potentially exposed prior to patching |
| Precedent | Widely characterized as one of the first well-documented cases of a largely autonomous AI agent independently executing an end-to-end intrusion — exploitation through exfiltration — without real-time human direction |
Recommendations
For Zammad Administrators
- Upgrade to Zammad version 7 immediately, or take any instance running an affected version (6.3.0 through 6.5.4, or any pre-7.1.0-alpha build) offline until patched.
- Do not assume any pre-7.1.0-alpha deployment is safe by default —
CVE-2026-102490's affected range extends across a wide span of historical releases; confirm the specific build against Zammad's advisory rather than relying on a general "upgrade to 7" shorthand. - Audit Zammad session logs and service-account activity for anomalous, rapid-fire command sequences consistent with automated, non-human operation — the compressed timeline in this incident is itself a detection signal.
For Security Teams
- Treat internally hosted helpdesk and ticketing platforms as high-value targets, not administrative overhead — DIVD's own breach originated in exactly this kind of internal-tooling deployment.
- Build detection logic around the speed of an attack chain, not just its individual steps; an agentic intrusion that completes session hijack, RCE, privilege escalation, and exfiltration within seconds will outrun alerting pipelines tuned for human-paced attacker behavior.
- Apply network segmentation as a standing control, not an incident-response afterthought — DIVD explicitly credits segmentation with stopping this intrusion from spreading beyond the initially compromised host.
For Open-Source Software Maintainers and Users
- Coordinate zero-day disclosure with affected vendors before publishing technical detail, as DIVD did with Zammad, to give downstream administrators a patching window.
- Expect autonomous AI agents to become a more common post-exploitation tool; incident response playbooks built around human attacker pacing and behavior may need revision.
- Subscribe to vendor and CERT advisories for widely embedded open-source tooling (ticketing systems, CMSs, CI/CD platforms) — Zammad's 2,000-plus customer base illustrates how a single chained zero-day pair in shared infrastructure can carry outsized blast radius.
Key Takeaways
- DIVD, a Dutch vulnerability-disclosure nonprofit, confirmed its own network was breached via two zero-days — CVE-2026-102489 and CVE-2026-102490 — in the open-source Zammad ticketing platform it uses internally.
- The post-exploitation activity was driven by an autonomous AI agent that chained session hijacking, remote code execution, and privilege escalation to root in seconds, without direct human operator control at each step.
- DIVD says the agent's behavior was "loud and very, very messy" and left extensive self-documented reasoning, which the organization used to reconstruct the attack — a rare level of visibility into automated attacker decision-making.
- The attacker accessed other internal services and exfiltrated data, but network segmentation and incident response stopped further lateral movement into DIVD's broader network.
- Zammad version 7 addresses both flaws; DIVD discovered them with Merlon Security and urges affected administrators to upgrade or take vulnerable instances offline immediately, while noting
CVE-2026-102490's affected range extends up to builds prior to7.1.0-alpha. - The incident is being widely cited as one of the first well-documented cases of a largely autonomous AI agent independently executing a full intrusion chain — from exploitation to data exfiltration — a pattern defenders should now factor into detection and response planning.