The Dutch Institute for Vulnerability Disclosure (DIVD) says attackers broke into its systems through two previously unknown flaws in Zammad, the open-source help desk software, and that the way the attack ran points to an AI agent. DIVD published the details in its incident case file, with a second file for the Zammad vulnerabilities.
According to DIVD, first access came on September 21, 2026, and the team noticed on September 22. DIVD assigned CVE-2026-102489, a session hijack that leads to remote code execution as the Zammad user, and CVE-2026-102490, a local privilege escalation from that user to root. The first affects Zammad 6.3.0 to 6.5.4. DIVD says versions 7.0.0 to 7.1.3 contain it but are not exploitable under the conditions it tested. The second affects all versions, including the latest alpha. DIVD lists a patch as available and advises users to upgrade to Zammad 7 or take the software offline.
DIVD says network segmentation and its incident response team stopped the attackers from going deeper, though some damage was done. Volunteer data left the network, including email addresses and possibly contact details, which makes it easier to pose as a DIVD volunteer. DIVD asks anyone who gets an odd message from it to check with communications@divd.nl first.
Why it matters: the organization that scans the internet for vulnerable systems was itself reached through a help desk product. DIVD says the agent decided each next step itself and went from session hijack to root in seconds. It has scanned for exposed Zammad instances and says it is notifying their owners.
Our read: a chain that takes seconds leaves no room for a human to step in mid-attack, so the controls that mattered were the ones in place beforehand, segmentation and logging. Teams running Zammad should check their logs against the indicators DIVD published. We have covered agents working at machine speed before, including three off-the-shelf agents that hit 27 retailers, and argued that a scope prompt is not an AI agent control.
Source: DIVD CSIRT, case DIVD-2026-00014