Dutch Institute for Vulnerability Disclosure Breached via Zammad 0-Days

Dutch Institute for Vulnerability Disclosure Breached via Zammad 0-Days

Dutch Institute for Vulnerability Disclosure was breached through two Zammad 0-days in an AI-powered attack that led to remote code execution and root access.

Listen to this article

0:00 —

Press play to start listening

The Dutch Institute for Vulnerability Disclosure (DIVD) has confirmed that attackers breached its infrastructure through two previously unknown vulnerabilities in Zammad, the open-source customer-support and ticketing platform used by its incident-response team.

The attackers first breached DIVD’s systems on September 21, 2026. DIVD detected suspicious activity the following day, blocked access to its data-centre infrastructure and began a forensic investigation with incident-response company Merlon Security.

According to DIVD’s investigation, the attackers chained two Zammad vulnerabilities to hijack a session, remotely execute code as the local zammad user and then elevate their privileges to root. This gave them access to other services and allowed information to be exfiltrated.

The first vulnerability, tracked as CVE-2026-102489, carries a CVSS score of 8.7. DIVD said it affects Zammad versions 6.3.0 through 6.5.4. The underlying vulnerable code is also present in versions 7.0.0 through 7.1.3, but DIVD said environmental conditions prevent exploitation on those releases. When chained with the second vulnerability, CVE-2026-102489 carries a CVSS-BT score of 9.4, rated critical.

The second vulnerability, tracked as CVE-2026-102490, is a local privilege-escalation vulnerability that DIVD said allowed the compromised Zammad account to obtain root access. Its CVE record gives it a CVSS score of 8.5 when exploited locally, while CVE-2026-102490 carries a CVSS-BT score of 9.4 when chained with CVE-2026-102489, rated critical. DIVD said versions from 1.5.0 through the 7.1.0 alpha release were affected.

The breach exposed information belonging to DIVD volunteers. The organisation confirmed that DIVD email addresses and possibly other contact details were exfiltrated, although it has not yet established which volunteers or data fields were affected.

Attackers also accessed the CSIRT ticketing system, which contained email conversations between DIVD and organisations or researchers seeking assistance. DIVD warned that the extracted material may include IP addresses of vulnerable systems, vulnerability reports and portions of credential dumps with masked passwords. The system did not contain DIVD’s initial vulnerability notifications.

DIVD described the intrusion as an “agentic AI-powered attack.” Investigators found scripts containing comments in which the apparent AI agent explained and justified its actions. DIVD said the attack was fast and automated, with the agent selecting its next steps independently, but also described its logic as messy. No known threat group has been connected to the incident, and the AI assessment has not been independently verified.

Network segmentation and the decision to isolate the affected infrastructure prevented the attackers from moving further into DIVD’s environment. Its accounting systems and bank account are managed externally, and investigators have found no evidence that those systems were compromised. Reviews of its Google Workspace, Slack, GitHub, GitLab, Jira and Confluence environments remain ongoing.

Zammad has disputed part of DIVD’s disclosure. The vendor said CVE-2026-102489 is exploitable only on unsupported Zammad 6.5 and older releases, while Zammad 7.0 and later are not affected in practice.

It nevertheless hardened the relevant code in version 7.2.0. For CVE-2026-102490, Zammad said it had not received technical details from DIVD and could not verify the vulnerability, its scope or affected versions.

Zammad recommends updating to version 7.2.0, while DIVD advises moving to Zammad 7 or taking affected instances offline. Administrators should preserve application and network logs before upgrading and use DIVD’s indicator-checking script to search for evidence of compromise.

I am a UK-based cybersecurity journalist with a passion for covering the latest happenings in cybersecurity and tech world. I am also into gaming, reading and investigative journalism.
Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts