Oossa

Dutch bug‑hunting org DIVD hacked via AI‑driven Zammad exploits

DIVD says AI‑enabled attackers used two zero‑day bugs in Zammad to steal volunteer email addresses on Sep 21, 2026.

OossaPublished by Oossa: 1 min read

FlyD · Unsplash

On Sep 21, 2026 the Dutch Institute for Vulnerability Disclosure (DIVD) was breached. Attackers used two newly discovered zero‑day flaws in the Zammad ticketing system to hijack sessions, run code as the Zammad user, and then gain root privileges. Within seconds the chain of exploits gave the intruders full control of DIVD’s servers. The hackers stole email addresses and possibly other contact details of DIVD’s volunteer security researchers. DIVD warned anyone receiving a suspicious DIVD email to verify it by contacting communications@divd.nl.

What the bugs were and how they were fixed

The two vulnerabilities are catalogued as CVE‑2026‑102489 and CVE‑2026‑102490. CVE‑2026‑102489 lets unauthenticated attackers execute code remotely and steal user sessions; CVE‑2026‑102490 lets a local user elevate to root. Both received a high CVSS score of 9.4 when assessed in the chained scenario. Versions 6.3.0‑6.5.4 and 7.0.0‑7.1.3 of Zammad are affected by the first bug, while all versions are vulnerable to the second. DIVD’s advisory urges all Zammad users to upgrade to version 7 or take the service offline.

Response and investigation

DIVD’s team discovered the breach on Sep 22, 2026, cut off access to its data‑center systems and enlisted Merlon Security for incident response. By Sep 24 they reported the vulnerabilities to the Zammad vendor, notified the Dutch Data Protection Authority and the National Cyber Security Centre, and involved police. The organization described the attack as “agentic AI‑powered,” noting that the malicious script automatically decided its next steps and left AI‑generated comments in the code – something a human attacker rarely does.

Why it matters

Volunteer security researchers at DIVD may receive phishing emails that now appear more credible because their contact details were exposed. Verifying any unexpected DIVD communication helps avoid social‑engineering attacks. The incident also shows that AI‑assisted attackers can chain multiple bugs quickly, prompting other organizations using Zammad to check their versions and apply patches promptly.

Was this article useful?
Share

Read next

Oossa · Newsletter

The week in AI, explained

Every Monday: the stories worth knowing, in plain language. Free, no spam.