The Dutch Institute for Vulnerability Disclosure (DIVD) says attackers breached its network by exploiting two zero-day vulnerabilities in the open-source Zammad ticketing system. The nonprofit said an AI agent carried out the attack autonomously, choosing its next steps without outside direction.
The flaws, identified as CVE-2026-102489 and CVE-2026-102490, enabled session hijacking, remote code execution and escalation from the Zammad user account to root privileges, DIVD said. After exploiting them, the attacker accessed other services and read and exfiltrated data from DIVD systems within seconds, aided by AI automation.
DIVD said network segmentation and incident response prevented the attacker from moving deeper into its network. The investigation is ongoing. The organization reconstructed the incident from explanations the AI agent left about its decisions.
DIVD discovered the vulnerabilities with Merlon Security and notified Zammad. It is also alerting users with vulnerable instances. DIVD recommends upgrading to version 7, which it considers safe, or taking the instance offline as soon as possible.
Zammad is an open-source helpdesk and support ticketing platform. The company says its service has more than 2,000 customers and 55,000 users. DIVD said it plans to share further incident updates tomorrow.
Comments
0No comments yet. Be the first to comment.