The Dutch Institute for Vulnerability Disclosure (DIVD), a non-profit organization dedicated to finding and reporting security flaws, has disclosed that it was the target of a sophisticated cyberattack on September 21, 2026. The attackers exploited two chained zero-day vulnerabilities in the Zammad open-source helpdesk software. The flaws, CVE-2026-102489 (Remote Code Execution) and CVE-2026-102490 (Privilege Escalation), allowed the attackers to gain complete control of the affected system. DIVD has characterized the incident as a novel "agentic AI-powered attack," suggesting a high degree of automation and speed in the execution of the attack chain. While some data was exfiltrated, network segmentation prevented a deeper compromise of DIVD's infrastructure. Zammad users are urged to take their instances offline or upgrade immediately.
The attack leveraged a chain of two previously unknown vulnerabilities in the Zammad ticketing system:
root user, granting them complete control over the server.Chaining these two vulnerabilities gives an unauthenticated, remote attacker a direct path to full system compromise. DIVD's description of the attack as "agentic AI-powered" suggests the use of an autonomous or semi-autonomous agent that could identify the vulnerabilities and execute the multi-stage exploit with minimal human intervention and at machine speed.
The vulnerabilities affect the following versions of the Zammad helpdesk system:
DIVD has strongly advised all organizations running Zammad to either take their instances offline or upgrade to a patched version as soon as it becomes available.
The attack against DIVD on September 21 is the first known instance of these zero-days being exploited. The attackers successfully hijacked sessions, executed code, and escalated privileges to root within seconds. They were able to exfiltrate some data from the compromised Zammad instance and attempted to pivot to other services. However, DIVD's network segmentation controls successfully contained the breach and prevented the attackers from accessing more sensitive parts of their network. DIVD has since notified Zammad of the vulnerabilities and published a hunting script to help other organizations check for signs of compromise.
This incident is significant for two reasons. First, it demonstrates that even security-focused organizations like DIVD are targets of sophisticated attacks. Second, the reported use of an "agentic AI-powered" method marks a potential evolution in attack techniques, where AI is not just a tool for reconnaissance but an active agent in the exploitation process. For any organization using Zammad, the impact is critical. A compromise could expose sensitive helpdesk tickets, customer data, internal communications, and provide a powerful pivot point into the broader corporate network. The speed of the attack highlights that traditional, human-led detection and response may be too slow to counter such automated threats.
The following patterns may help identify vulnerable or compromised Zammad systems:
sh, bash) or network utilities (curl, wget) being spawned by the Zammad process./opt/zammad/Organizations using Zammad should act immediately.
Immediate action is required to mitigate this threat.
Applying the forthcoming patch from Zammad is the most critical step to prevent exploitation.
Mapped D3FEND Techniques:
Running the Zammad application in a containerized or sandboxed environment can help limit the impact of an RCE exploit.
Mapped D3FEND Techniques:
As demonstrated by DIVD's successful containment, segmenting the network prevents attackers from pivoting from the compromised host to other critical systems.
Mapped D3FEND Techniques:
The compromise of DIVD underscores the critical importance of network isolation. The Zammad server, like any public-facing application, should be placed in a dedicated, isolated network segment (DMZ). Strict firewall rules must be enforced to limit communication from this server to the internal network. Only essential, pre-approved connections to specific internal services (like databases or authentication servers) should be permitted. All other inbound connections from the Zammad server should be denied by default. This 'zero-trust' approach to network architecture was instrumental in preventing the attackers from moving laterally within DIVD's environment and is a crucial lesson for all organizations.
Given the RCE nature of CVE-2026-102489, host-based process monitoring is essential for detection. Security teams should deploy EDR agents or use native OS auditing to monitor process creation on Zammad servers. A baseline of normal process activity should be established. Alerts must be configured to trigger whenever the Zammad application process (e.g., puma) spawns unexpected child processes, particularly shells (/bin/sh, bash), scripting interpreters (python, perl), or network utilities (curl, wget, nc). This type of behavior is a strong indicator of a successful RCE exploit, and an automated alert can provide the early warning needed to initiate an incident response before significant damage occurs.
While awaiting a patch, organizations should review and harden the configuration of their Zammad instances and the underlying operating system. This includes running the Zammad services with the least privilege possible, not as root. File system permissions for the Zammad application directory (/opt/zammad/) should be tightened to prevent the application process from writing to unexpected locations. Additionally, implementing security modules like AppArmor or SELinux can create mandatory access control policies that restrict the application's capabilities, potentially preventing the privilege escalation step (CVE-2026-102490) from succeeding even if the initial RCE is achieved. These hardening measures provide defense-in-depth against both known and unknown vulnerabilities.
The Dutch Institute for Vulnerability Disclosure (DIVD) is compromised by the Zammad zero-day attack.
DIVD publicly discloses the incident and the two zero-day vulnerabilities.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.