The Dutch Institute for Vulnerability Disclosure (DIVD) recently faced a sophisticated cyber attack that leveraged two zero-day vulnerabilities found in Zammad, an open-source ticketing solution. The breach, which occurred on September 21, marked one of the first cases where AI automation played a significant role in the attack strategy. DIVD promptly initiated an incident response, blocking access to its infrastructure and notifying Dutch authorities. The investigation revealed that the attackers used two critical vulnerabilities: CVE-2026-102489, which allows unauthenticated remote code execution and session leakage, and CVE-2026-102490, which enables local privilege escalation to root. By combining these vulnerabilities, the attackers managed to hijack sessions, execute code remotely, and escalate privileges within seconds.
Despite the breach, network segmentation within DIVD's systems prevented the attackers from penetrating deeper into their environment. DIVD has reported these vulnerabilities to Zammad, which is currently working on a patch. The affected versions of Zammad are 6.3.0 to 6.5.4, while versions 7.0.0 to 7.1.3 also possess the flaws but are less susceptible due to environmental factors.
In response, DIVD advises all Zammad users to upgrade to version 7 or take their systems offline. The institute has also developed a verification script to help organizations identify indicators of compromise and is actively scanning for vulnerable Zammad instances to alert their owners. This incident highlights the growing impact of AI on cybersecurity, emphasizing the need for robust defenses against automated attacks.

