DIVD says Zammad zero-days enabled AI-driven network breach

DIVD says Zammad zero-days enabled AI-driven network breach
The Dutch Institute for Vulnerability Disclosure (DIVD) says its network breach was caused by chaining two zero-day flaws in the open-source Zammad ticketing system, leading to session hijacking, remote code execution, and root privilege escalation. DIVD and Merlon Security notified Zammad and advised users to upgrade to version 7 or take vulnerable instances offline immediately. #DIVD #Zammad #CVE-2026-102489 #CVE-2026-102490

Keypoints

  • DIVD says two Zammad zero-days enabled the breach.
  • The attack was carried out by an autonomous AI agent.
  • The flaws allowed session hijacking and remote code execution.
  • Attackers escalated from Zammad user to root in seconds.
  • DIVD urges users to upgrade to Zammad version 7 or take systems offline.

Read More: https://www.bleepingcomputer.com/news/security/divd-says-zammad-zero-days-enabled-ai-driven-network-breach/