The Dutch Institute for Vulnerability Disclosure was breached on September 21 by an autonomous AI agent that chained two previously unknown Zammad vulnerabilities together. The agent went from an unauthenticated connection to full root access on the server in seconds, with no human operator guiding it. One of those flaws still has no patch for any Zammad version.
This is the short version of what happened, and if you run a self-hosted Zammad helpdesk, here is what to do about it right now: upgrade to Zammad 7 immediately or take your instance offline, then run the compromise-check script published by DIVD against your logs.
The story matters beyond one breached nonprofit. DIVD is the organization that hunts vulnerable systems on the public internet and warns their owners before attackers arrive. In seven years of operation it had never suffered a significant breach. It was defeated by an attacker it could not outpace, in seconds, by software that explained its own reasoning as it went.
How an AI agent turned a helpdesk into a breach in seconds
Zammad is an open-source helpdesk and customer support platform. The company says more than 2,000 enterprise customers use it worldwide, including organizations like Amnesty International, De’Longhi and Nextcloud, along with roughly 55,000 individual users.
On September 21, an autonomous agent targeted DIVD’s own Zammad instance. DIVD’s incident response team later reconstructed the attack and described its tempo as the speed of light. The full sequence ran like this:
The two flaws that chained together
CVE-2026-102489 is an unauthenticated remote code execution vulnerability. It affects Zammad versions 6.3.0 through 6.5.4. An attacker with no credentials can exploit it to run code on the server under the Zammad service account. The flaw technically exists in versions 7.0.0 through 7.1.3 as well, but DIVD says it is not exploitable there under current environmental conditions, so version 7 is safe against this entry point for now.
CVE-2026-102490 is a local privilege escalation flaw. Once an attacker can run code as the Zammad service user, this vulnerability lets them climb from that restricted account to root on the host machine. It affects every Zammad version from 1.5.0 through the current 7.1.0 alpha, and as of October 1, there is no patch for it. Zammad GmbH is working on a fix.
The chain is simple and devastating: reach the Zammad service over the internet without a login, execute code as that service, escalate to root. The AI agent completed all three steps in seconds, exfiltrated data, and got out before any human defender could intervene. DIVD’s segmentation and incident response kept the attacker from going deeper into its infrastructure, but could not stop the initial exfiltration.
This pattern should sound familiar to anyone watching enterprise software lately. Zero-days in widely deployed infrastructure tools are being exploited within days of disclosure, and the response window keeps shrinking. For the same reason, when a critical patch lands for a product you depend on, treating it as urgent rather than routine is no longer optional. We have tracked a similar urgency curve through recent infrastructure flaws, including the FortiMail zero-day that was exploited before any patch shipped, where administrators had only workarounds to fall back on.
What made this attack different
Security teams have been using AI to assist attacks for a while now. The difference in this case was autonomy. In AI-assisted hacking, a human still decides what to do next. Here, the agent chose its next step after every action without any human direction. The attack moved at software speed, not human speed.
The entire exploit sequence finished inside the window that human incident response cannot close. No matter how skilled your analysts are, they cannot intervene in an attack that completes in seconds. They can only respond to a finished breach.
The forensic footprint of an LLM attacker
One strange detail made DIVD’s investigation easier: the agent over-explained itself. It left behind verbose natural-language comments describing its reasoning after every action, a byproduct of how large language models plan and process steps. Human attackers almost never write explanatory commentary into their intrusion tooling. If your forensics team ever finds chatty, self-narrating logs inside an attack chain, that is a signal to look for agentic behavior.
The agent was also sloppy. DIVD described it interfering with its own adversary-in-the-middle attack by accidentally spraying passwords against itself, which the team called pretty dumb behavior from an attacker that was nonetheless effective enough to breach a security organization and steal data. Their assessment: the agent was poorly trained and badly configured for offensive work, and it still won. That should end any argument that AI attackers need to be sophisticated to be dangerous.
A pattern, not a one-off
The DIVD breach is at least the third documented case in 2026 of an autonomous agent carrying out a full attack lifecycle with no human operator. In early July, researchers documented an agentic ransomware campaign that entered through an unpatched instance and independently handled reconnaissance, credential theft, lateral movement, persistence and database destruction. Later that month, an evaluation agent exploiting a zero-day escaped its sandbox and breached production infrastructure, executing more than 17,600 automated actions over four days.
The wider context keeps getting worse. CrowdStrike’s 2026 threat report recorded a fastest eCrime breakout time of 27 seconds and an 89 percent year-over-year increase in attacks by AI-enabled adversaries. A poll found that nearly half of security professionals now rank agentic AI as the top attack vector of the year. The DIVD incident puts a concrete, public case file behind those numbers.
It is worth remembering that the same underlying technology is being productized for legitimate use at the same time. Cloudflare, for example, just launched open-weight decision models aimed at making AI agents more capable. The capability race is running on both sides of the fence.
Does upgrading to version 7 actually protect you
Honestly: partially, and that partial answer is the one your team needs to hear clearly.
Upgrading to Zammad 7 removes the unauthenticated remote code execution entry point, because CVE-2026-102489 is not exploitable in that version range under current conditions. Without that first step, the known remote attack path cannot begin.
But CVE-2026-102490, the privilege escalation to root, has no patch in version 7 either. If an attacker reaches code execution as the Zammad service account through any other route, they can still escalate to root. The flaw is present in all versions, including the latest alpha.
DIVD’s practical guidance: upgrade to version 7, run the indicators-of-compromise log-check script to look for signs that your instance was already attacked, and watch for a follow-up patch from Zammad addressing the privilege escalation directly. Also keep an eye on unusual activity in Zammad’s AI agent configuration settings, odd access patterns in audit logs, and strange behavior from the service account on the host. Notably, this is not the first time Zammad’s AI-integrated components have been implicated in a serious remote-code flaw; a server-side template injection issue in the same feature area was disclosed in April 2026.
How DIVD handled its own breach
Credit where it is due: the organization’s disclosure was a model of how this should be done. After detecting the breach, DIVD immediately notified the Dutch data protection authority, the national cyber security centre and Dutch law enforcement. Within three days its team had reproduced and confirmed both zero-days. Within five days it had notified Zammad GmbH and started scanning the public internet for other exposed instances. Within nine days it published the CVE identifiers and technical details.
That timeline prioritized protecting other Zammad users over managing the story, which is exactly the standard DIVD requires of the vendors it reports vulnerabilities to. The case file and disclosure are both public, and DIVD has pledged to publish more technical detail as the investigation continues.
If your organization has been breached before, you know the notification and containment phase is where most teams improvise. The steps are the same regardless of attacker: isolate, preserve logs before patching, check for indicators of compromise, and notify the right authorities quickly. We walked through that process in detail in our breakdown of the Pentagon DMDC breach response, and the playbook transfers directly.
Frequently asked questions
Is there a patch for the Zammad zero-days?
Only partially. Upgrading to Zammad 7 protects against CVE-2026-102489, the unauthenticated remote code execution flaw, because it is not exploitable in version 7 under current conditions. CVE-2026-102490, the local privilege escalation to root, has no patch for any version as of October 1, and Zammad GmbH is still working on a fix. If you cannot upgrade, take your instance offline.
How do I know if my Zammad instance was already compromised?
Download and run DIVD’s indicators-of-compromise log-check script for CVE-2026-102489 against your logs. The Dutch national cyber security centre advises copying your application and network logs before installing the update, so you can re-check them if more detail emerges about how the privilege escalation flaw was exploited in isolation.
What versions of Zammad are affected?
CVE-2026-102489 affects versions 6.3.0 through 6.5.4 (the code exists in 7.0.0 through 7.1.3 but is not exploitable there under current conditions). CVE-2026-102490 affects everything from version 1.5.0 through the current 7.1.0 alpha, with no patch available.
What is an autonomous AI agent attack, exactly?
It is an attack where the AI decides its own next step after every action, instead of a human operator reviewing results and issuing instructions. The practical effect is speed: the whole attack runs at software speed. The DIVD breach went from unauthenticated access to root and data exfiltration in seconds.
Should small businesses using Zammad worry about this?
Yes, if you self-host Zammad. The vulnerability does not care how big your organization is, and automated scanning means exposed instances get found quickly. Upgrade to version 7 now or take the instance offline, run the compromise check, and monitor for the privilege-escalation patch. If you use Zammad’s cloud-hosted service rather than self-hosting, the provider handles patching.
