The Dutch Institute for Vulnerability Disclosure (DIVD) says its network breach was caused by chaining two zero-day flaws in the open-source Zammad ticketing system, leading to session hijacking, remote code execution, and root privilege escalation. DIVD and Merlon Security notified Zammad and advised users to upgrade to version 7 or take vulnerable instances offline immediately. #DIVD #Zammad #CVE-2026-102489 #CVE-2026-102490
Keypoints
- DIVD says two Zammad zero-days enabled the breach.
- The attack was carried out by an autonomous AI agent.
- The flaws allowed session hijacking and remote code execution.
- Attackers escalated from Zammad user to root in seconds.
- DIVD urges users to upgrade to Zammad version 7 or take systems offline.