<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/divd-says-zammad-zero-days-enabled-ai-driven-network-breach-qqveci5qx" -->

---
title: DIVD says Zammad zero-days enabled AI-driven network breach
description: DIVD, the Dutch Institute for Vulnerability Disclosure, disclosed that its own network was breached through a chain of two zero-day vulnerabilities in the...
canonical: https://daily.dev/posts/divd-says-zammad-zero-days-enabled-ai-driven-network-breach-qqveci5qx
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: DIVD says Zammad zero-days enabled AI-driven network breach | daily.dev
og:description: DIVD, the Dutch Institute for Vulnerability Disclosure, disclosed that its own network was breached through a chain of two zero-day vulnerabilities in the...
og:url: https://daily.dev/posts/divd-says-zammad-zero-days-enabled-ai-driven-network-breach-qqveci5qx
og:image: https://api.daily.dev/og/posts/qQVEci5QX.png
og:image:alt: DIVD says Zammad zero-days enabled AI-driven network breach
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# DIVD says Zammad zero-days enabled AI-driven network breach

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 2 min read · 0 upvotes · 0 comments

## Summary

DIVD, the Dutch Institute for Vulnerability Disclosure, disclosed that its own network was breached through a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system, tracked as CVE-2026-102489 and CVE-2026-102490. The flaws allowed session hijacking, remote code execution, and privilege escalation from the Zammad user to root, which an autonomous AI agent exploited within seconds without human direction. Network segmentation and incident response prevented deeper lateral movement, though the investigation continues. DIVD, working with Merlon Security, is notifying other Zammad users and recommends upgrading to version 7 or taking vulnerable instances offline immediately.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/divd-says-zammad-zero-days-enabled-ai-driven-network-breach>

## Questions this post answers

### What CVEs are behind the Zammad zero-day breach of DIVD's network?

CVE-2026-102489 and CVE-2026-102490 are the two zero-day vulnerabilities in the open-source Zammad ticketing system that were chained together. Used together, they allowed session hijacking, remote code execution, and privilege escalation from the Zammad user account to root, which an autonomous AI agent exploited within seconds during the attack on DIVD's network.

_Teams running Zammad can track fast-moving CVE disclosures like this one on daily.dev to patch before attackers strike._

### What Zammad version should I upgrade to after the recent zero-day exploits?

Zammad users are advised to upgrade to version 7, which DIVD considers safe from the exploited zero-day chain, or take vulnerable instances offline immediately if upgrading isn't possible right away. The vulnerabilities were discovered by DIVD in collaboration with Merlon Security and reported to Zammad, which is now being used to alert other affected users.

_daily.dev helps developers running self-hosted tools like Zammad stay ahead of urgent security upgrades._

### How did an AI agent breach DIVD's network so quickly using the Zammad vulnerabilities?

An AI agent moved autonomously through DIVD's systems, deciding its own next steps without human direction, and completed session hijacking, remote code execution, and root privilege escalation in a matter of seconds. DIVD could reconstruct the incident in detail because the agent left behind clear explanations of its own decisions during the attack.

_Security practitioners weighing agentic AI's offensive potential follow breach breakdowns like this on daily.dev._

## Similar posts on daily.dev

- [Zoom warns of critical account takeover vulnerability](https://daily.dev/posts/zoom-warns-of-critical-account-takeover-vulnerability-n5d4se3mt) · BleepingComputer · 1 upvotes · 0 comments
- [0DIN is open-sourcing AI security and the hard-earned knowledge behind it](https://daily.dev/posts/0din-is-open-sourcing-ai-security-and-the-hard-earned-knowledge-behind-it-oq2jlcpzs) · Mozilla · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#zero-day](https://daily.dev/tags/zero-day)

[View this post on daily.dev](https://daily.dev/posts/divd-says-zammad-zero-days-enabled-ai-driven-network-breach-qqveci5qx)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"DIVD says Zammad zero-days enabled AI-driven network breach","url":"https://daily.dev/posts/divd-says-zammad-zero-days-enabled-ai-driven-network-breach-qqveci5qx","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/divd-says-zammad-zero-days-enabled-ai-driven-network-breach-qqveci5qx"},"datePublished":"2026-09-30T19:53:00.699Z","dateModified":"2026-10-01T21:34:15.067Z","description":"DIVD, the Dutch Institute for Vulnerability Disclosure, disclosed that its own network was breached through a chain of two zero-day vulnerabilities in the...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e74f41f893e58149c057ad2c98d5ec1a?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e74f41f893e58149c057ad2c98d5ec1a?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/divd-says-zammad-zero-days-enabled-ai-driven-network-breach-qqveci5qx","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,zero-day","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"DIVD says Zammad zero-days enabled AI-driven network breach"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/divd-says-zammad-zero-days-enabled-ai-driven-network-breach-qqveci5qx#faq","mainEntity":[{"@type":"Question","name":"What CVEs are behind the Zammad zero-day breach of DIVD's network?","acceptedAnswer":{"@type":"Answer","text":"CVE-2026-102489 and CVE-2026-102490 are the two zero-day vulnerabilities in the open-source Zammad ticketing system that were chained together. Used together, they allowed session hijacking, remote code execution, and privilege escalation from the Zammad user account to root, which an autonomous AI agent exploited within seconds during the attack on DIVD's network. Teams running Zammad can track fast-moving CVE disclosures like this one on daily.dev to patch before attackers strike."}},{"@type":"Question","name":"What Zammad version should I upgrade to after the recent zero-day exploits?","acceptedAnswer":{"@type":"Answer","text":"Zammad users are advised to upgrade to version 7, which DIVD considers safe from the exploited zero-day chain, or take vulnerable instances offline immediately if upgrading isn't possible right away. The vulnerabilities were discovered by DIVD in collaboration with Merlon Security and reported to Zammad, which is now being used to alert other affected users. daily.dev helps developers running self-hosted tools like Zammad stay ahead of urgent security upgrades."}},{"@type":"Question","name":"How did an AI agent breach DIVD's network so quickly using the Zammad vulnerabilities?","acceptedAnswer":{"@type":"Answer","text":"An AI agent moved autonomously through DIVD's systems, deciding its own next steps without human direction, and completed session hijacking, remote code execution, and root privilege escalation in a matter of seconds. DIVD could reconstruct the incident in detail because the agent left behind clear explanations of its own decisions during the attack. Security practitioners weighing agentic AI's offensive potential follow breach breakdowns like this on daily.dev."}}]}
```

