DIVD agentic-AI breach: Zammad CVE-2026-102489/102490 zero-day chain (session→RCE→root) — Bleeping 30 Sep
Dutch Institute for Vulnerability Disclosure (DIVD) CSIRT (24 September 2026, “It was a matter of when, not if…”): after nearly seven years the volunteer vuln-disclosure nonprofit confirmed it was breached. Modus operandi “indicates that this is an agentic AI powered attack”; infrastructure access blocked; third-party IR engaged; Autoriteit Persoonsgegevens, NCSC-NL and police notified; treat as worst-case assume-breach until proven otherwise. UPDATE via BleepingComputer (29 Sep, citing DIVD Monday update): attack described as “loud and very very messy”; after initial exploit of an undisclosed technical vulnerability (explicitly not Citrix NetScaler), an automated AI agent performed post-exploitation, choosing next steps autonomously, leaving verbose decision comments, and interfering with its own adversary-in-the-middle / password-spraying path — researchers characterise the agent as poorly trained/configured, aiding reconstruction. Purpose and full impact still unclear; DIVD intends a more detailed public update on 1 October and victim notification for the same vulnerability when ready. Krebs (28 Sep): DIVD says incident does not appear related to ShinyHunters / prior volunteer Umbreon matter. UPDATE 30 Sep 2026 — BleepingComputer: initial access was a chain of two Zammad helpdesk zero-days CVE-2026-102489 and CVE-2026-102490 (discovered with Merlon Security) enabling session hijacking, RCE, and escalation to root in seconds under AI automation, then lateral access/exfiltration; segmentation limited deeper movement. DIVD recommending Zammad users upgrade to version 7 or take instances offline; alerting other vulnerable operators; further public detail still expected. Product patch path filed separately as zammad-102489-102490-20260930. Primary: DIVD CSIRT 24 Sep; wires: BleepingComputer 29–30 Sep.
- Product
- DIVD infrastructure — initial access via Zammad helpdesk CVE-2026-102489/102490 (not Citrix NetScaler)
- Versions
- Zammad: upgrade to 7.x per DIVD/Bleeping 30 Sep (or offline). Exact exploited build not fully enumerated publicly.
- Exploited in Australia?
- unknown
- Patch to
- Zammad operators: upgrade to 7.x immediately or take instances offline (see desk zammad-102489-102490-20260930). Orgs that share tooling/data with DIVD: watch DIVD CSIRT victim notices. Defenders: treat agentic post-exploitation (autonomous next-step loops, verbose agent comments, noisy/sloppy logic) as a live TTP class alongside the Zammad initial-access chain.
Primary: DIVD CSIRT — It was a matter of when, not if… (24 Sep 2026) · Vendor: DIVD CSIRT (victim / primary notice) · CVE: CVE-2026-102489, CVE-2026-102490 · BleepingComputer — DIVD: Zammad zero-days enabled AI-driven breach (30 Sep 2026)
