Case update: DIVD-2026-00014 - When, not if... The Dutch Institute for Vulnerability Disclosure (DIVD) disclosed that it was breached by hackers who gained access through AI agents exploiting two 0-day vulnerabilities in Zammad, tracked as CVE-2026-102489 and CVE-2026-102490. DIVD's Crisis Management Team said first malicious access occurred on 21 Sep 2026, the organization detected the activity on 22 Sep 2026 and blocked access to all systems in its datacenter, and an incident response team began a forensic investigation with Merlon Security the same day. DIVD opened case DIVD-2026-00015 for target and victim notification of the two known exploited vulnerabilities and is scanning for vulnerable Microtick appliances. DIVD-2026-00014 - When, not if... | Our reference | DIVD-2026-00014 https://csirt.divd.nl/cases/DIVD-2026-00014 | | Case lead | DIVD Crisis Management Team | | Author | Various | | Researcher s | | | CVE s | | | Product | nil | | Versions | nil | | Status | Open | | Last modified | 30 Sep 2026 18:14 CEST | Summary DIVD got hacked through AI agents and is currently investigating the breach. Incident investigation is ongoing. We have identified that the hackers got in via two 0-day vulnerabilities in Zammad. We have assigned the CVE IDs CVE-2026-102489 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-102489 and CVE-2026-102490 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-102490 to these vulnerabilities and started case DIVD-2026-00015 https://csirt.divd.nl/cases/DIVD-2026-00015 to do target and victim notification for these two known exploited vulnerabilities. We will update this page shortly with more information on the incident. Timeline | Date | Description | |---|---| | 21 Sep 2026 | First access by malicious actor on DIVD systems | | 22 Sep 2026 | DIVD becomes aware of malicious activity. Access to all systems in the datacenter is blocked | | 22 Sep 2026 | Incident response team formed and forensic investigation started together with Merlon Security | | 29 Sep 2026 | Publication of casefile | | 29 Sep 2026 | Publication of overview of which data is compromised and which data is not. | gantt title DIVD-2026-00014 - When, not if... dateFormat YYYY-MM-DD axisFormat %e %b %Y section Case DIVD-2026-00014 - When, not if... still open :2026-09-22, 2026-10-07 section Events First access by malicious actor on DIVD systems : milestone, 2026-09-21, 0d DIVD becomes aware of malicious activity. Access to all systems in the datacenter is blocked : milestone, 2026-09-22, 0d Incident response team formed and forensic investigation started together with Merlon Security : milestone, 2026-09-22, 0d Publication of casefile : milestone, 2026-09-29, 0d Publication of overview of which data is compromised and which data is not. : milestone, 2026-09-29, 0d What we are doing DIVD is currently scanning for vulnerable Microtick appliances and notifying affected parties.