DIVD Hacked Using Chained Zammad Zero-Days (CVE-2026-102489)

Dutch Security Institute Hacked via AI-Powered Zammad Zero-Days

HIGH
October 1, 2026
5m read
VulnerabilityCyberattackThreat Intelligence

Impact Scope

Affected Companies

Dutch Institute for Vulnerability Disclosure (DIVD)

Geographic Impact

Netherlands (national)

Related Entities

Products & Tech

Zammad Artificial Intelligence

CVE Identifiers

CVE-2026-102489
CRITICAL
CVSS:9.4
CVE-2026-102490
CRITICAL
CVSS:9.4

Full Report

Executive Summary

The Dutch Institute for Vulnerability Disclosure (DIVD), a non-profit organization dedicated to finding and reporting security flaws, has disclosed that it was the target of a sophisticated cyberattack on September 21, 2026. The attackers exploited two chained zero-day vulnerabilities in the Zammad open-source helpdesk software. The flaws, CVE-2026-102489 (Remote Code Execution) and CVE-2026-102490 (Privilege Escalation), allowed the attackers to gain complete control of the affected system. DIVD has characterized the incident as a novel "agentic AI-powered attack," suggesting a high degree of automation and speed in the execution of the attack chain. While some data was exfiltrated, network segmentation prevented a deeper compromise of DIVD's infrastructure. Zammad users are urged to take their instances offline or upgrade immediately.


Vulnerability Details

The attack leveraged a chain of two previously unknown vulnerabilities in the Zammad ticketing system:

  1. CVE-2026-102489 (CVSS 9.4): An unauthenticated remote code execution (RCE) and session hijacking vulnerability. This flaw allows an attacker to remotely execute commands on the Zammad server without needing any credentials.
  2. CVE-2026-102490 (CVSS 9.4): A local privilege escalation (LPE) vulnerability. Once an attacker has initial access to the system (via the RCE), this flaw can be used to escalate their privileges to the root user, granting them complete control over the server.

Chaining these two vulnerabilities gives an unauthenticated, remote attacker a direct path to full system compromise. DIVD's description of the attack as "agentic AI-powered" suggests the use of an autonomous or semi-autonomous agent that could identify the vulnerabilities and execute the multi-stage exploit with minimal human intervention and at machine speed.

Affected Systems

The vulnerabilities affect the following versions of the Zammad helpdesk system:

  • Exploitable versions: 6.3.0 to 6.5.4
  • Vulnerable but not exploitable versions: 7.0.0 to 7.1.3

DIVD has strongly advised all organizations running Zammad to either take their instances offline or upgrade to a patched version as soon as it becomes available.

Exploitation Status

The attack against DIVD on September 21 is the first known instance of these zero-days being exploited. The attackers successfully hijacked sessions, executed code, and escalated privileges to root within seconds. They were able to exfiltrate some data from the compromised Zammad instance and attempted to pivot to other services. However, DIVD's network segmentation controls successfully contained the breach and prevented the attackers from accessing more sensitive parts of their network. DIVD has since notified Zammad of the vulnerabilities and published a hunting script to help other organizations check for signs of compromise.

Impact Assessment

This incident is significant for two reasons. First, it demonstrates that even security-focused organizations like DIVD are targets of sophisticated attacks. Second, the reported use of an "agentic AI-powered" method marks a potential evolution in attack techniques, where AI is not just a tool for reconnaissance but an active agent in the exploitation process. For any organization using Zammad, the impact is critical. A compromise could expose sensitive helpdesk tickets, customer data, internal communications, and provide a powerful pivot point into the broader corporate network. The speed of the attack highlights that traditional, human-led detection and response may be too slow to counter such automated threats.


Cyber Observables — Hunting Hints

The following patterns may help identify vulnerable or compromised Zammad systems:

Type
Log Source
Value
Zammad production.log
Description
Monitor for unusual API calls or errors that could indicate exploitation attempts against the application.
Type
Process Name
Value
Unusual child processes of the Zammad application server (e.g., Puma).
Description
Look for shells (sh, bash) or network utilities (curl, wget) being spawned by the Zammad process.
Type
Network Traffic Pattern
Value
Outbound connections from the Zammad server to unknown IPs.
Description
A compromised server may initiate connections to an attacker's C2 infrastructure.
Type
File Path
Value
/opt/zammad/
Description
Check for newly created or modified files in the Zammad installation directory, which could be web shells or other malicious payloads.

Detection & Response

Organizations using Zammad should act immediately.

  1. Run Hunting Script: Use the hunting script published by DIVD to check for indicators of compromise on Zammad instances.
  2. Process Monitoring: D3-PA: Process Analysis. Implement enhanced monitoring of processes on Zammad servers. Alert on any suspicious child processes spawned by the main Zammad application, especially shells or reverse-shell clients.
  3. Network Isolation: If compromise is suspected, immediately isolate the Zammad server from the network to prevent further data exfiltration or lateral movement. Preserve the system for forensic analysis.

Remediation Steps

Immediate action is required to mitigate this threat.

  1. Take System Offline: DIVD's primary recommendation is to take all Zammad instances offline until a patch is available and can be applied.
  2. Upgrade Immediately: Once Zammad releases a patched version, organizations must upgrade without delay. D3-SU: Software Update.
  3. Assume Compromise: If a system was running a vulnerable version, it should be considered compromised. After patching, a full investigation should be conducted, and if possible, the system should be rebuilt from a known-good state. All credentials and secrets stored on or accessible from the Zammad server should be rotated.

Timeline of Events

1
September 21, 2026
The Dutch Institute for Vulnerability Disclosure (DIVD) is compromised by the Zammad zero-day attack.
2
September 30, 2026
DIVD publicly discloses the incident and the two zero-day vulnerabilities.
3
October 1, 2026
This article was published

MITRE ATT&CK Mitigations

Applying the forthcoming patch from Zammad is the most critical step to prevent exploitation.

Mapped D3FEND Techniques:

Running the Zammad application in a containerized or sandboxed environment can help limit the impact of an RCE exploit.

Mapped D3FEND Techniques:

As demonstrated by DIVD's successful containment, segmenting the network prevents attackers from pivoting from the compromised host to other critical systems.

Mapped D3FEND Techniques:

D3FEND Defensive Countermeasures

The compromise of DIVD underscores the critical importance of network isolation. The Zammad server, like any public-facing application, should be placed in a dedicated, isolated network segment (DMZ). Strict firewall rules must be enforced to limit communication from this server to the internal network. Only essential, pre-approved connections to specific internal services (like databases or authentication servers) should be permitted. All other inbound connections from the Zammad server should be denied by default. This 'zero-trust' approach to network architecture was instrumental in preventing the attackers from moving laterally within DIVD's environment and is a crucial lesson for all organizations.

Given the RCE nature of CVE-2026-102489, host-based process monitoring is essential for detection. Security teams should deploy EDR agents or use native OS auditing to monitor process creation on Zammad servers. A baseline of normal process activity should be established. Alerts must be configured to trigger whenever the Zammad application process (e.g., puma) spawns unexpected child processes, particularly shells (/bin/sh, bash), scripting interpreters (python, perl), or network utilities (curl, wget, nc). This type of behavior is a strong indicator of a successful RCE exploit, and an automated alert can provide the early warning needed to initiate an incident response before significant damage occurs.

While awaiting a patch, organizations should review and harden the configuration of their Zammad instances and the underlying operating system. This includes running the Zammad services with the least privilege possible, not as root. File system permissions for the Zammad application directory (/opt/zammad/) should be tightened to prevent the application process from writing to unexpected locations. Additionally, implementing security modules like AppArmor or SELinux can create mandatory access control policies that restrict the application's capabilities, potentially preventing the privilege escalation step (CVE-2026-102490) from succeeding even if the initial RCE is achieved. These hardening measures provide defense-in-depth against both known and unknown vulnerabilities.

Timeline of Events

1
September 21, 2026

The Dutch Institute for Vulnerability Disclosure (DIVD) is compromised by the Zammad zero-day attack.

2
September 30, 2026

DIVD publicly discloses the incident and the two zero-day vulnerabilities.

Sources & References

Zammad Zero-Days Exploited in AI-Powered DIVD Hack
SecurityWeek (securityweek.com) •October 1, 2026

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

zero-dayAIRCEprivilege escalationZammadhelpdesk

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.