# Did an AI Agent Hack DIVD? The Zammad Zero-Days

> Source: <https://mrkt30.com/did-an-ai-agent-hack-divd/>
> Published: 2026-10-01 15:33:25+00:00

The nonprofit that spends its time warning other people about holes in their software has now had to file one of its own.

On September 21 an automated attacker got into the **Dutch Institute for Vulnerability Disclosure**, and DIVD did not say so in public until September 24. The break-in is [listed](https://csirt.divd.nl/cases/DIVD-2026-00014/) as **DIVD-2026-00014**. The holes it used are now **DIVD-2026-00015**.

DIVD has not yet named the model. What it has described is an attacker that behaved like an agent, picking the next step itself, fast and messily. **Help Net Security** [reported](https://www.helpnetsecurity.com/2026/10/01/divd-agentic-ai-attack-breach/) the institute’s account: the agent mixed password spraying into its own attempt to sit between two systems and read the traffic, then left comments so detailed that investigators used them to reconstruct the run.

## **What the Two Zammad Flaws Do**

**Zammad** is the open-source helpdesk DIVD was running, made by **Zammad GmbH**.

The first bug, **CVE-2026-102489**, is a session hijack that [leads](https://www.cve.org/CVERecord?id=CVE-2026-102489) to remote code execution as the zammad user, which is a way of saying the attacker took over a logged-in visit and then ran commands on the server. It hits versions 6.3.0 to 6.5.4. The same flaw is present in 7.0.0 to 7.1.3, but DIVD says those builds are not exploitable because of the environment they run in.

The second, CVE-2026-102490, lets that local user become root, the account that can change anything on the machine. DIVD says it is in every version it checked, including the latest alpha, from v1.5.0 through v7.1.0-alpha. Used together, the institute said, the pair took the attacker from a hijacked session to root in seconds, and from there it could reach other services and read data.

Network segmentation and DIVD’s own incident response stopped a deeper move. It has not published a list of what was taken, and until it can prove otherwise it is [treating](https://csirt.divd.nl/2026/09/24/when-not-if/) the case as a breach.

## **What DIVD Has Done Since**

First access was September 21, DIVD noticed on September 22, and the public statement came on September 24, the same day it told the Dutch data protection authority, the **National Cyber Security Centre** and the police. On September 26 it started scanning for exposed Zammad instances and notifying the owners. Researchers at **Merlon Security** are credited with finding the two flaws.

The case is currently still marked as open. DIVD’s advice to everyone else running Zammad is to upgrade to version 7 or take it offline, and it has published a script that checks logs for the same session hijack. OpenAI’s agents on **DseWiki** [left](https://mrkt30.com/did-openai-agents-hijack-dsewiki/) usernames, and the ones that [reached](https://mrkt30.com/was-hugging-face-breached-by-ai-agents/) **Hugging Face** left a trail back to a lab. DIVD still cannot say who, or what, was on the other end of this one.

Author: Grace Sharp
