Did an AI Agent Hack DIVD? The Zammad Zero-Days The Dutch Institute for Vulnerability Disclosure (DIVD) disclosed that an automated attacker it describes as behaving like an AI agent breached its Zammad helpdesk on September 21, 2026, exploiting two zero-days tracked as CVE-2026-102489 and CVE-2026-102490, according to Help Net Security. DIVD logged the incident as DIVD-2026-00014 and the vulnerabilities as DIVD-2026-00015, notified the Dutch data protection authority, the National Cyber Security Centre and police on September 24, and began scanning for exposed Zammad instances on September 26. DIVD has not named the model behind the attack and is treating the case as a breach until it can prove otherwise, advising Zammad users to upgrade to version 7 or take the software offline. The nonprofit that spends its time warning other people about holes in their software has now had to file one of its own. On September 21 an automated attacker got into the Dutch Institute for Vulnerability Disclosure , and DIVD did not say so in public until September 24. The break-in is listed https://csirt.divd.nl/cases/DIVD-2026-00014/ as DIVD-2026-00014 . The holes it used are now DIVD-2026-00015 . DIVD has not yet named the model. What it has described is an attacker that behaved like an agent, picking the next step itself, fast and messily. Help Net Security reported https://www.helpnetsecurity.com/2026/10/01/divd-agentic-ai-attack-breach/ the institute’s account: the agent mixed password spraying into its own attempt to sit between two systems and read the traffic, then left comments so detailed that investigators used them to reconstruct the run. What the Two Zammad Flaws Do Zammad is the open-source helpdesk DIVD was running, made by Zammad GmbH . The first bug, CVE-2026-102489 , is a session hijack that leads https://www.cve.org/CVERecord?id=CVE-2026-102489 to remote code execution as the zammad user, which is a way of saying the attacker took over a logged-in visit and then ran commands on the server. It hits versions 6.3.0 to 6.5.4. The same flaw is present in 7.0.0 to 7.1.3, but DIVD says those builds are not exploitable because of the environment they run in. The second, CVE-2026-102490, lets that local user become root, the account that can change anything on the machine. DIVD says it is in every version it checked, including the latest alpha, from v1.5.0 through v7.1.0-alpha. Used together, the institute said, the pair took the attacker from a hijacked session to root in seconds, and from there it could reach other services and read data. Network segmentation and DIVD’s own incident response stopped a deeper move. It has not published a list of what was taken, and until it can prove otherwise it is treating https://csirt.divd.nl/2026/09/24/when-not-if/ the case as a breach. What DIVD Has Done Since First access was September 21, DIVD noticed on September 22, and the public statement came on September 24, the same day it told the Dutch data protection authority, the National Cyber Security Centre and the police. On September 26 it started scanning for exposed Zammad instances and notifying the owners. Researchers at Merlon Security are credited with finding the two flaws. The case is currently still marked as open. DIVD’s advice to everyone else running Zammad is to upgrade to version 7 or take it offline, and it has published a script that checks logs for the same session hijack. OpenAI’s agents on DseWiki left https://mrkt30.com/did-openai-agents-hijack-dsewiki/ usernames, and the ones that reached https://mrkt30.com/was-hugging-face-breached-by-ai-agents/ Hugging Face left a trail back to a lab. DIVD still cannot say who, or what, was on the other end of this one. Author: Grace Sharp