An AI Agent Breached Vulnerability-Disclosure Institute DIVD by Chaining Zammad Zero-Days: Session Hijack to Root in Seconds, Both Flaws Now on CISA KEV
An AI Agent Breached Vulnerability-Disclosure Institute DIVD by Chaining Zammad Zero-Days: Session Hijack to Root in Seconds, Both Flaws Now on CISA KEV
The Dutch Institute for Vulnerability Disclosure (DIVD) — the organization that coordinates disclosure for vulnerable systems across the Netherlands — was itself breached on September 21 by what investigators describe as an autonomous AI agent chaining two previously unknown flaws in Zammad, the open-source helpdesk platform. According to a Sysdig report shared with Cyber Security News, the attacker moved from a hijacked session to root access on the server "within seconds." DIVD detected the intrusion the following day and blocked access to its data center systems; by October 1, investigators had confirmed the theft of volunteer email addresses, while possible exposure of contact details, support correspondence and sensitive research remained under investigation.
The chain is a two-step escalation through the internet-facing application. CVE-2026-102489 (Sysdig severity 8.7) enables session hijacking followed by remote code execution as the Zammad service account, with no existing privileges required — the exploitable chain affects Zammad 6.3.0 through 6.5.4, while the underlying flaw also exists in 7.0.0 through 7.1.3 where environmental conditions prevent exploitation. CVE-2026-102490 (severity 8.5) then elevates the service account to root, affecting versions 1.5.0 through 7.1.0-alpha. Together they carry a critical chain score of 9.4. CISA added both flaws to its Known Exploited Vulnerabilities catalog on October 2, giving federal agencies until October 5 — today — to mitigate.
What has researchers calling this an AI-assisted intrusion is the attacker's behavior. The agent attempted password spraying and an interception attack that interfered with each other, and its scripts contained explanatory comments claiming its actions were harmless — evidence that helped investigators recognize the nature of the breach. Sysdig compares the behavior to earlier autonomous intrusions such as JADEPUFFER, and no human operator or group has been publicly linked to the attack. The most consequential finding: DIVD believes its security response ticket archive was partially extracted — a store that can contain vulnerability reports, follow-up requests about exposed systems, and credential dump extracts with masked passwords. Preliminary findings show no known impact on accounting information, bank accounts or initial security notifications.
At DIVD, network segmentation limited the blast radius, but investigators found signs of compromise in ticketing, project support and operational systems — which does not mean every affected system lost data. Sysdig recommends upgrading to Zammad 7.0.0 or later (with later coverage recommending 7.2.0), or taking vulnerable installations offline, and stresses that blocking the initial entry point is not proof a host is clean.
What Should You Do?
- If you run an internet-facing Zammad 6.3.0-6.5.4, upgrade today — 7.0.0 or later, 7.2.0 recommended — or take it offline; the CISA KEV deadline is October 5.
- Preserve application and web server logs before rebuilding, then run DIVD's log-checking script — and remember a clean result does not rule out compromise; hunt unfamiliar processes and files too.
- Monitor service accounts specifically: unexpected command shells, transitions to root, connections to unfamiliar destinations, widespread credential-file reads, repeated failed logins and unusually large uploads.
- Pre-authorize automated containment. When the time from entry to root is measured in seconds, response is a policy decision you make before the alert fires — not a human one after it.
The WAF Angle
The helpdesk portal is the classic forgotten attack surface: an internet-facing web app that handles attachments, forms and unauthenticated traffic, administered by support teams rather than security. This chain shows why that's a problem — session integrity flaws plus application-level RCE mean the distance from "someone abused the login flow" to "root on the box" is one hop, not a defended boundary. Inline inspection and rate limiting on helpdesk endpoints buy real time against the probing and spraying phases, but the KEV clock says patching is the control that matters this week. The second lesson is logging: DIVD caught this intrusion in a day because its internet-facing systems produced evidence — an attacker that leaves comments in its own scripts is noisy, but only for teams who are recording. And for teams still treating autonomous AI attacks as a simulated exercise — like the Gemini incident we covered in September — this is the real-world version: an agent that found the door, walked through it, escalated, and left notes.