Trusence Every claim has a source
Last updated 4 October 2026 Search Türkçe
← All stories
Security

DIVD says two Zammad zero-days let an AI agent breach its network

DIVD is urging Zammad users to move to version 7 or shut affected instances down while the two flaws are fixed.

The Dutch Institute for Vulnerability Disclosure says a breach of its network came from chaining two zero-day bugs in Zammad, an open-source ticketing and helpdesk platform, and that the intrusion was carried out by an AI agent that moved on its own. The flaws, now tracked as CVE-2026-102489 and CVE-2026-102490, let the attacker hijack sessions, execute code remotely, and escalate from the Zammad user to root in seconds. DIVD says it was able to reconstruct the incident because the agent left clear explanations of its actions, and that network segmentation kept the attacker from spreading farther into its environment. The group found the issues with Merlon Security, notified Zammad, and is telling users to move to version 7 or take affected instances offline while the investigation continues.

Why it matters

The report shows how chained application bugs can let an autonomous agent take over a server quickly and still be contained by network boundaries. For users of the ticketing platform, the immediate issue is exposure: if an instance is affected, it should be upgraded or taken offline before the same path is used again.

Sources

  • BleepingComputer