Zammad Zero-Days Exploited in AI-Powered DIVD Hack

The Dutch Institute for Vulnerability Disclosure (DIVD) has been hacked in a sophisticated AI-powered attack that exploited two previously unknown vulnerabilities in the open-source user support platform Zammad. The attackers used this combination of flaws to gain unauthorized access, hijack sessions, and escalate privileges to root level in mere seconds.

The hack occurred on September 21st, prompting DIVD’s immediate response, including blocking access to their infrastructure and notifying Dutch authorities. According to an investigation, the attack was carried out by an agentic AI-powered system that utilized two zero-day vulnerabilities in Zammad: CVE-2026-102489 and CVE-2026-102490. These flaws allowed unauthenticated attackers to achieve remote code execution and leak user sessions, while also enabling local users to elevate their privileges.

The combination of these two weaknesses proved particularly devastating as it enabled the attackers to pivot from the Zammad instance to other services within DIVD’s network. However, thanks to robust network segmentation practices, they were unable to gain deeper access into the environment. The hackers did manage to exfiltrate data before being detected and stopped.

DIVD has reported the zero-day vulnerabilities to Zammad, which is working on a fix. In the meantime, users of Zammad versions 6.3.0 to 6.5.4 are advised to upgrade to version 7 or take their systems offline. DIVD has also published a verification script to help organizations detect indicators of compromise and is actively scanning for vulnerable instances.

What makes this attack particularly noteworthy is its use of AI, which represents a new frontier in threat vectors. The combination of human ingenuity and artificial intelligence poses a significant challenge for defenders, as it can accelerate the speed at which attacks unfold. However, it also highlights the importance of vigilance and preparedness in the face of emerging threats.

As we continue to navigate this evolving landscape, it is essential to prioritize security practices that account for AI-powered attacks. This includes maintaining up-to-date software, implementing robust network segmentation, and staying informed about emerging threats. By doing so, organizations can better protect themselves against sophisticated attacks like this one and reduce the risk of falling victim to similar breaches in the future.

Ultimately, the DIVD hack serves as a stark reminder of the importance of security awareness and preparedness in today’s threat landscape. As AI continues to play an increasingly significant role in both cybersecurity and cyber threats, it is crucial that we remain proactive and adaptable in our approach to defense.


Source: SecurityWeek — 2026-10-01