As reported by SecurityAffairs, the Dutch Institute for Vulnerability Disclosure (DIVD) has publicly confirmed a breach of its own infrastructure through two zero-day vulnerabilities in Zammad, an open-source helpdesk and ticketing platform it used internally. The vulnerabilities — CVE-2026-102489 and CVE-2026-102490 — when chained together, allowed the attacker to hijack sessions, execute remote code, and escalate from the Zammad service account to root privileges in seconds. DIVD attributes the remarkable speed of the attack to the involvement of an AI agent that autonomously executed post-exploitation steps without waiting for human direction.

Security Impact: As reported by SecurityAffairs, the Dutch Institute for Vulnerability Disclosure (DIVD) has publicly confirmed a breach of its own infrastructure through two zero-day vulnerabilities in Zammad, an open-source helpdesk and ticketing platform it used internally.

Vulnerability Summary

CVEVendor / ProductSeverityPatch Status
CVE-2026-102489Zammad (open-source helpdesk)High / Critical (chained)Fixed in Zammad 7.0
CVE-2026-102490Zammad (open-source helpdesk)High / Critical (chained)Fixed in Zammad 7.0

Neither individual vulnerability technical detail has been fully published at the time of analysis, but DIVD has confirmed that the chain enables session hijacking leading to authenticated remote code execution, followed by local privilege escalation to root. Affected deployments include any Zammad instance running versions prior to 7.0. Zammad reports over 2,000 customers and approximately 55,000 users globally.

Why This Matters

The DIVD breach is significant on three distinct levels.

1. The target paradox. DIVD is one of Europe's most respected volunteer vulnerability disclosure organizations. If an organization whose entire mission is finding and disclosing vulnerabilities can be compromised through unpatched software in its own environment, the operational reality for resource-constrained IT and security teams everywhere is stark. No organization is immune to the basics: exposed services, unpatched dependencies, and insufficient segmentation.

2. The AI acceleration factor. The most notable detail in DIVD's disclosure is the attribution of attack speed to an AI agent. Traditional privilege escalation chains — especially those requiring lateral movement decisions — often take an attacker minutes to hours of manual interaction. DIVD states the attacker moved from initial access to root in seconds. This suggests the AI agent was autonomously performing reconnaissance, selecting exploitation paths, and executing commands in a tight loop. This is a meaningful shift from AI-assisted attacks (where a human drives and the AI suggests) to AI-agentic attacks (where the agent drives and the human supervises or is absent). Defenders should assume that agentic tooling will increasingly compress dwell-time-to-objective across all attack phases.

3. The blast radius of helpdesk software. Ticketing systems like Zammad are high-value targets because they centralize sensitive data: internal communications, attachments, credentials shared in support tickets, customer PII, and integrations with directory services. Compromising a helpdesk platform often provides a natural pivot point into mail systems, identity providers, and file shares — exactly the lateral movement DIVD experienced.

Who Is at Risk

  • Any organization running Zammad versions prior to 7.0 — especially internet-exposed instances.
  • Helpdesk and IT operations teams who rely on Zammad for internal or external ticketing with integration into SSO, mail, or directory services.
  • Nonprofits, research institutions, and volunteer organizations — which often have limited patching cadences and lean security teams.
  • Managed service providers hosting Zammad instances for multiple tenants.

Shield53 Recommendations

Immediate Actions:

  • Patch or isolate now. Upgrade all Zammad instances to version 7.0. If patching cannot be completed immediately, take the instance offline or restrict access via VPN/IP allowlisting. DIVD explicitly recommends this.
  • Run DIVD's log-check script. DIVD has published a script to check Zammad logs for signs of abuse. Run it against any instance that was exposed during the vulnerability window.
  • Review Zammad service account permissions. The privilege escalation chain moved from the Zammad service user to root. Audit what the Zammad service account can access on the host OS and reduce permissions to the minimum required. Consider running Zammad in a container or dedicated user with no sudo capabilities.
  • Validate segmentation. DIVD credited network segmentation with limiting the blast radius. Confirm that your helpdesk platform cannot directly reach identity providers, mail systems, or file shares without explicit firewall rules.
  • Rotate credentials. Any credentials, API keys, or tokens stored in or accessible by Zammad should be rotated. This includes integration secrets for mail, SSO, and directory services.
  • Hunt for indicators of compromise. Look for anomalous session activity, unexpected process spawns under the Zammad service account, and outbound connections from the Zammad host.

Strategic actions for the agentic threat era:

  • Reduce attack surface exposure times. Agentic attacks compress exploitation timelines. Organizations cannot rely on detection-and-response cycles measured in hours. Mean-time-to-patch for externally exposed services must shift from days to hours for critical vulnerabilities.
  • Implement aggressive containment for high-value services. Host-based intrusion detection, EDR with automated isolation, and just-in-time access models become more important when attacker dwell time drops to seconds.

The DIVD incident is a preview of what agentic attacks look like in practice: not science fiction, not a future scenario — a breach that happened this week, to a team of security professionals, in seconds. The defense is not a new product category. It is faster patching, tighter segmentation, and accepting that the attacker timeline has fundamentally changed.