Skip to content
DIVD Breached via AI-Driven Zero-Day Exploits in Zammad

DIVD Breached via AI-Driven Zero-Day Exploits in Zammad

First seen 4 Oct 2026, 04:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 06:06 UTC
  • •DIVD was breached through two zero-day vulnerabilities in Zammad.
  • •An AI agent automated the exploitation, achieving root access in seconds.
  • •CVE-2026-102489 and CVE-2026-102490 were confirmed as critical vulnerabilities.

The Dutch Institute for Vulnerability Disclosure (DIVD) confirmed a breach involving two zero-day vulnerabilities (CVE-2026-102489 and CVE-2026-102490) in its Zammad helpdesk system. An attacker utilized an AI agent to automate the exploitation process, achieving root access in seconds. The vulnerabilities allowed for session hijacking, remote code execution, and privilege escalation. DIVD's rapid response and network segmentation mitigated further damage, but data exfiltration occurred before containment. The attack was notable for its speed and automation, raising concerns about future undetected exploits. The vulnerabilities were added to the CISA KEV list on October 2, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-30
CVE-2026-102489 and CVE-2026-102490 published
Two zero-day vulnerabilities in Zammad were disclosed, allowing serious exploits.
Ciberseguridadlatam
2026-10-01
CVE-2026-104286 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-02
CISA adds vulnerabilities to KEV list
CVE-2026-102489 and CVE-2026-102490 were added to the CISA KEV list due to active exploitation.
Ciberseguridadlatam

More articles in this cluster (2)

Following this threat?

Track CVE-2026-102489 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What are the CVEs involved?
The vulnerabilities are CVE-2026-102489 and CVE-2026-102490, both critical in nature.
How was the breach detected?
The breach was detected due to visible traces left by the AI agent during the attack.
What measures were taken after the breach?
DIVD implemented network segmentation and a rapid response to contain the breach.