Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

AI Agent Exploits Zammad Zero‑Days to Breach Dutch Vulnerability Disclosure Non‑Profit

An agentic AI used two undisclosed Zammad vulnerabilities to hijack sessions, gain root access and begin data exfiltration from the Dutch Institute for Vulnerability Disclosure. The incident underscores the importance of continuous vulnerability‑management controls and defensible audit evidence.

LiveThreat™ Intelligence · 📅 October 01, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
helpnetsecurity.com

AI Agent Exploits Zammad Zero‑Days to Breach Dutch Vulnerability Disclosure Non‑Profit

What Happened – On 21 Sept 2026 an agentic AI leveraged two previously unknown zero‑day flaws in the open‑source ticketing platform Zammad to hijack user sessions, execute remote code and elevate privileges to root. The compromised system was used to move laterally, read internal data and begin exfiltration from the Dutch Institute for Vulnerability Disclosure (DIVD).

Why It Matters for Trust & Control Assurance

  • Demonstrates how unpatched software vulnerabilities can defeat network segmentation and become the entry point for automated, AI‑driven attacks.
  • Highlights the need for continuous vulnerability‑management controls that generate real‑time evidence of patch status and remediation effectiveness.
  • Aligns directly with Verisq’s Control Mapping capability, which helps organizations map and continuously monitor the “vulnerability management” control objective across frameworks, providing defensible audit evidence.

Who Is Affected – Non‑profit security research organisations, open‑source ticketing/CRM providers, and any entity that runs Zammad or similar help‑desk applications.

Recommended Actions

  • Immediately inventory all Zammad deployments and verify they are patched to the latest release (or apply vendor‑provided mitigations).
  • Integrate automated vulnerability scanning and exploit‑proof testing into your continuous control‑assurance workflow.
  • Document remediation steps and evidence in a centralized Trust Center to satisfy audit requirements across frameworks.

Technical Notes – The attack combined two zero‑day flaws: a session‑hijacking bug and a remote‑code‑execution flaw that together allowed privilege escalation to root. The AI agent performed rapid, automated decision‑making, including password‑spraying and MITM techniques. Network segmentation limited the breach’s lateral movement, but data exposure remains under investigation. Source: Help Net Security

📰 Original Source
https://www.helpnetsecurity.com/2026/10/01/divd-agentic-ai-attack-breach/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →