Home › Intelligence › Brief
BREACH BRIEF🔴 Critical Breach

Zero‑Day Flaws in Zammad Ticketing System Enable AI‑Driven Network Breach at DIVD

DIVD’s network was breached after an attacker exploited two newly disclosed Zammad zero‑days, using an autonomous AI agent to gain root and exfiltrate data. The incident underscores the importance of continuous third‑party vulnerability monitoring and rapid patch evidence for audit readiness.

LiveThreat™ Intelligence · 📅 October 01, 2026· 📰 bleepingcomputer.com
🔴
Severity
Critical
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
bleepingcomputer.com

Zero‑Day Flaws in Zammad Ticketing System Enable AI‑Driven Network Breach at DIVD

What Happened – The Dutch Institute for Vulnerability Disclosure (DIVD) confirmed that an attacker leveraged two newly disclosed zero‑day vulnerabilities (CVE‑2026‑102489, CVE‑2026‑102490) in the open‑source Zammad help‑desk platform to hijack sessions, execute remote code and gain root privileges. An autonomous AI agent used the chain of flaws to move laterally and exfiltrate data from DIVD’s network within seconds.

Why It Matters for Trust & Control Assurance

  • Demonstrates the risk of unpatched third‑party software – a core control area for continuous vendor risk monitoring and evidence of timely remediation.
  • Highlights the need for automated vulnerability detection and rapid patch deployment to maintain a defensible audit trail.
  • Shows that network segmentation and incident‑response playbooks are essential controls that limited the breach’s scope.

Who Is Affected – Organizations that self‑host or consume Zammad (customer‑support, ITSM, SaaS providers), especially those in nonprofit, professional services, and any sector relying on open‑source ticketing solutions.

Recommended Actions

  • Upgrade all Zammad instances to version 7 or later immediately, or temporarily take vulnerable instances offline.
  • Conduct an inventory of third‑party components and map them to a continuous vulnerability‑management program.
  • Verify that patch‑management evidence is collected and stored for audit readiness.
  • Review network‑segmentation policies and incident‑response playbooks to ensure rapid containment.

Source: BleepingComputer

Technical Notes – CVE‑2026‑102489 and CVE‑2026‑102490 allow session hijacking, remote code execution, and privilege escalation from a Zammad user to root. The attacker employed an AI‑driven agent that autonomously selected exploitation steps, leaving detailed decision logs that aided reconstruction. Network segmentation prevented deeper lateral movement. Source: same as above

📰 Original Source
https://www.bleepingcomputer.com/news/security/divd-says-zammad-zero-days-enabled-ai-driven-network-breach/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your third-party risk controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →