Ciberseguridadlatam DIVD Breached via AI-Driven Zero-Day Exploits in Zammad
Article Content
- •DIVD was breached through two zero-day vulnerabilities in Zammad.
- •An AI agent automated the exploitation, achieving root access in seconds.
- •CVE-2026-102489 and CVE-2026-102490 were confirmed as critical vulnerabilities.
The Dutch Institute for Vulnerability Disclosure (DIVD) confirmed a breach involving two zero-day vulnerabilities (CVE-2026-102489 and CVE-2026-102490) in its Zammad helpdesk system. An attacker utilized an AI agent to automate the exploitation process, achieving root access in seconds. The vulnerabilities allowed for session hijacking, remote code execution, and privilege escalation. DIVD's rapid response and network segmentation mitigated further damage, but data exfiltration occurred before containment. The attack was notable for its speed and automation, raising concerns about future undetected exploits. The vulnerabilities were added to the CISA KEV list on October 2, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-102489 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What are the CVEs involved?
How was the breach detected?
What measures were taken after the breach?
Continue Reading
Vulnerabilities in Zammad Ticketing System Under Active Exploitation Two vulnerabilities (CVE-2026-102489 and CVE-2026-102490) have been identified in the Zammad ticketing system, affecting all versions up to 7.1.3. CVE-2026-102489 allows session hijacking leading to remote code execution in versions 6.3.0 to 6.5.4, while CVE-2026-102490 enables local privilege escalation to root…
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…