Dutch Institute for Vulnerability Disclosure Breached via Zammad 0-Day Exploit
Attackers exploited two zero-day vulnerabilities in Zammad to breach the Dutch Institute for Vulnerability Disclosure (DIVD), leading to data exfiltration and system compromise.
Breach Details
The Dutch Institute for Vulnerability Disclosure (DIVD) confirmed its systems were infiltrated through two undisclosed security flaws in the Zammad open-source customer-support and ticketing platform. The breach, attributed to an AI-driven attack, resulted in remote code execution and full system control. The intrusion occurred on September 21, 2026, with suspicious activity detected the following day. DIVD immediately restricted access to its data-center infrastructure and engaged Merlon Security for a forensic analysis.
Intrusion Timeline
The investigation revealed that attackers exploited two Zammad vulnerabilities to hijack a session, execute code as the local zammad user, and escalate privileges to root. This allowed access to additional services and the exfiltration of sensitive data.
Investigation Findings
The first vulnerability, designated CVE-2026-102489, has a CVSS score of 8.7 and affects Zammad versions 6.3.0 through 6.5.4. The second flaw, CVE-2026-102490, is a local privilege-escalation vulnerability that enabled attackers to gain root access. When combined, its CVSS-BT score reaches 9.4, classifying it as critical.
Impact of the Breach
The breach exposed data linked to DIVD volunteers, including addresses and contact details, though the exact scope remains under investigation. Attackers also accessed the CSIRT ticketing system, which contained communications between DIVD and external entities or researchers. The stolen data may include IP addresses of vulnerable systems, vulnerability reports, and partial credential dumps with obscured passwords.
Vulnerabilities
CVE-2026-102489
This vulnerability affects Zammad versions 6.3.0 through 6.5.4, with the vulnerable code also present in versions 7.0.0 to 7.1.3, though environmental factors may limit its exploitability.
CVE-2026-102490
This local privilege-escalation flaw impacts versions 1.5.0 through the 7.1.0 alpha release. Zammad has not received technical details from DIVD and cannot confirm the vulnerability’s scope or affected versions.
Data Exposed
The stolen data may include IP addresses of vulnerable systems, vulnerability reports, and partial credential dumps with obscured passwords. Notably, the system did not hold DIVD’s initial vulnerability disclosures.
AI-Powered Attack
DIVD described the attack as “agentic AI-powered,” citing scripts with comments from the AI agent that outlined its actions. The intrusion was rapid and automated, with the AI making independent decisions, though its operational logic was deemed disorganized.
Zammad’s Response
Zammad has contested parts of DIVD’s disclosure, stating that CVE-2026-102489 is only exploitable on unsupported Zammad 6.5 and older versions, with Zammad 7.0 and later considered unaffected. The vendor has addressed the issue in version 7.2.0. For CVE-2026-102490, Zammad noted it has not received technical details from DIVD and cannot confirm the vulnerability’s scope or affected versions.
Recommendations
Zammad advises users to update to version 7.2.0, while DIVD recommends migrating to Zammad 7 or disconnecting affected instances. Administrators are urged to retain application and network logs before upgrading and to use DIVD’s indicator-checking script to identify potential compromises.
