An autonomous AI agent breached the Dutch Institute for Vulnerability Disclosure (DIVD) after chaining two previously undisclosed vulnerabilities in the Zammad helpdesk platform, turning an initial application compromise into root access within seconds.
The incident, first detected on September 22 after the attacker accessed DIVD systems a day earlier, offers a stark example of how agentic attacks can compress reconnaissance, exploitation, privilege escalation, and data theft into a machine-speed operation.
DIVD said the intruder’s behavior indicated an agentic AI-powered attack rather than a conventional operator-led intrusion.
The organization characterized the activity as “loud and very messy,” noting that the attacker made automated, non-deterministic choices at speed and left unusually verbose comments in scripts explaining why certain actions were being taken.
Those artifacts helped investigators reconstruct the operation, but did not prevent the attacker from obtaining root-level access and exfiltrating data.
When chained, however, the vulnerabilities carry a critical CVSS score of 9.4 because an unauthenticated remote attacker can obtain code execution as the Zammad service account and subsequently escalate to root.
CVE-2026-102489 affects Zammad versions 6.3.0 through 6.5.4. DIVD said the vulnerability can enable session leakage and remote code execution as the zammad user.
The issue also exists in Zammad versions 7.0.0 through 7.1.3, but is not exploitable under the environmental conditions assessed by DIVD.
The second vulnerability CVE-2026-102490, affects Zammad releases from version 1.5.0 through 7.1.0-alpha.
It enables the local zammad user to elevate privileges to root, meaning organizations remain exposed to the privilege-escalation issue even if an attacker obtains local execution by a path other than the RCE vulnerability.
DIVD confirmed that volunteer email addresses were exfiltrated and said volunteer contact details may also have been taken.
Sysdig Researchers observed that, the attack relied on CVE-2026-102489, a remote code execution vulnerability in Zammad, and CVE-2026-102490, a local privilege-escalation vulnerability. Individually, DIVD scored the bugs at CVSS 8.7 and 8.5, respectively.
The organization is continuing to investigate possible impact across its CSIRT ticketing system, project-support environment, collaboration platforms, source-code repositories, IT support systems, and sensitive vulnerability-research datasets.
It warned that the exposed information may make it easier for adversaries to impersonate DIVD volunteers in subsequent social-engineering or phishing campaigns.
The compromise illustrates why helpdesk infrastructure is a high-value target.
Such systems commonly hold support correspondence, internal workflow data, database credentials, mail settings, API tokens, and integration secrets.
Root access on a helpdesk server can therefore become a pivot point into broader corporate services.
DIVD said network segmentation and its decision to block access to all systems in its datacenter helped prevent the attackers from moving deeper into the environment.
It began a forensic investigation with Merlon Security, notified relevant parties and Dutch authorities, disclosed the vulnerabilities to Zammad, and launched a separate case to identify and notify exposed Zammad instances.
The case reinforces that defenders cannot wait for signatures when a zero-day is involved.
Security teams should investigate Zammad application processes that spawn shells, execute unfamiliar binaries, download tooling, or establish new outbound connections.
A service account such as zammad changing effective privileges to root, creating root-owned child processes, or writing to privileged paths should be treated as a high-confidence compromise signal.
Organizations running affected Zammad versions should urgently assess exposure, preserve Zammad and reverse-proxy logs before rebuilding systems, and treat any evidence of exploitation as a full-host compromise.
Credentials stored on or accessible from the server should be rotated, while the helpdesk environment should be isolated with tightly restricted east-west access and default-deny outbound connectivity.
The DIVD breach demonstrates that AI-driven intrusion operations do not need flawless stealth to be dangerous.
Even a poorly orchestrated autonomous agent can exploit a narrow window between vulnerability discovery and mitigation then reach root before human-led response processes can catch up.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…