Zammad Zero-Day Vulnerabilities Exploited in AI-Powered DIVD Attack

www.news4hackers.com-zammad-zero-day-vulnerabilities-exploited-in-ai-powered-divd-attack-zammad-zero-day-vulnerabilities-exploited-in-ai-powered-divd-attack

Experts reveal how AI-driven tactics exploited unpatched Zammad vulnerabilities in a major cyberattack on the Dutch Institute for Vulnerability Disclosure (DIVD).

Overview of the Attack

The Dutch Institute for Vulnerability Disclosure (DIVD) suffered a cyberattack involving two unpatched vulnerabilities in the open-source helpdesk platform Zammad. The breach, detected on September 21, triggered immediate containment measures, including restrictions on access to the organization’s systems. DIVD initiated a comprehensive investigation and coordinated with Dutch regulatory authorities.

Technical Details of the Vulnerabilities

The attack utilized an automated artificial intelligence-driven approach, marking a novel tactic in cyber threats. DIVD’s analysis revealed the exploitation of two zero-day flaws in Zammad, which facilitated unauthorized access and system compromise.

Key Vulnerabilities Exploited

The first vulnerability, CVE-2026-102489 (CVSS score 9.4), allowed unauthenticated adversaries to execute arbitrary code and extract user session data. The second, CVE-2026-102490 (CVSS score 9.4), enabled privilege escalation from a local user to root access. Together, these flaws enabled attackers to hijack sessions, deploy remote code, and escalate privileges within seconds.

Impact and Containment Measures

Following initial compromise, threat actors expanded their reach across connected systems, exfiltrating data. However, DIVD’s network segmentation efforts limited the scope of the breach. The organization acknowledged ongoing investigations into potential additional compromises but confirmed containment of the attack.

Affected and Secure Versions

Zammad versions 6.3.0 through 6.5.4 are affected by the vulnerabilities, while versions 7.0.0 to 7.1.3 remain secure due to environmental restrictions. DIVD urged all Zammad users to either upgrade to version 7 or isolate affected instances.

Response and Mitigation Efforts

The institute released a verification tool to identify indicators of compromise (IoCs) and is actively monitoring for vulnerable systems. The attack underscores the evolving threat landscape, where AI-driven techniques exploit software weaknesses at unprecedented speeds. DIVD’s findings highlight the urgency of patch management and proactive security measures in mitigating risks associated with zero-day vulnerabilities.

“DIVD’s analysis revealed the exploitation of two zero-day flaws in Zammad, which facilitated unauthorized access and system compromise.”



About Author

en_USEnglish