Post

Dutch Institute for Vulnerability Disclosure Breached via Zammad 0-Days

Dutch Institute for Vulnerability Disclosure Breached via Zammad 0-Days

Dutch Institute for Vulnerability Disclosure Breached via Zammad 0-Days 🚨

The Dutch Institute for Vulnerability Disclosure (DIVD) has confirmed that attackers breached its infrastructure through two previously unknown vulnerabilities in Zammad, the open-source customer-support and ticketing platform used by its incident-response team.

The attackers first breached DIVD’s systems on September 21, 2026. DIVD detected suspicious activity the following day, blocked access to its data-center infrastructure, and began a forensic investigation with incident-response company Merlon Security. According to DIVD’s investigation, the attackers chained two Zammad vulnerabilities to hijack a session, remotely execute code as the local Zammad user, and then elevate their privileges to root. This gave them access to other services and allowed information to be exfiltrated.

Vulnerabilities Overview 🔍

  • CVE-2026-102489: CVSS score of 8.7, affecting Zammad versions 6.3.0 through 6.5.4.
  • CVE-2026-102490: A local privilege-escalation vulnerability with a CVSS score of 8.5 when exploited locally.

When chained, these vulnerabilities carry a critical CVSS-BT score of 9.4. The breach exposed information belonging to DIVD volunteers, including email addresses and possibly other contact details. Attackers also accessed the CSIRT ticketing system, which contained email conversations between DIVD and organizations or researchers seeking assistance.

Attack Description 🤖

DIVD described the intrusion as an “agentic AI-powered attack.” Investigators found scripts containing comments in which the apparent AI agent explained and justified its actions. The attack was fast and automated, with the agent selecting its next steps independently, but its logic was described as messy.

Network segmentation and the decision to isolate the affected infrastructure prevented the attackers from moving further into DIVD’s environment. Zammad has disputed part of DIVD’s disclosure, stating that CVE-2026-102489 is exploitable only on unsupported Zammad 6.5 and older releases, while Zammad 7.0 and later are not affected in practice.

For more details, you can read the full article here: Read full article

This post is licensed under CC BY 4.0 by the author.