Blog

DIVD hacked via two Zammad zero-days: why patching alone will not stop an agentic attack

DIVD was compromised via two Zammad zero-days and points to an agentic-AI method. What decision-makers must now arrange in vulnerability management.

· By

A rack of stacked hardware units with one slid forward and disconnected, a network cable hanging loose beside it, while an administrator watches from a distance.
Deliberately taking a publicly reachable system offline is a rehearsed option, not a panic decision, against rapidly chained vulnerabilities.Image: IamVera.ai — original editorial illustration

DIVD was compromised on 21 September 2026 via two zero-days in Zammad; according to DIVD the method pointed to an agentic-AI attack. The lesson for decision-makers: treat patching, segmentation, privilege restriction and logging as one chain, because automated attackers combine vulnerabilities faster than human response times allow.

The Dutch Institute for Vulnerability Disclosure (DIVD) describes in its case report that it fell victim to a breach itself. The attacker used two previously unknown vulnerabilities in Zammad, a helpdesk system that DIVD used internally. According to DIVD, the method matched what it calls an agentic-AI attack. In this article we use that term for an attack in which software autonomously carries out several follow-up steps; that is an interpretive framework, not an independently established reconstruction of every action.

What exactly happened at DIVD and which vulnerabilities played a role?

DIVD reports that the breach took place on 21 September 2026 and that network segmentation and incident response helped to limit further lateral movement. In a separate vulnerability analysis of Zammad DIVD published the technical details and mitigation advice.

The chain is described there precisely. CVE-2026-102489 enables session hijacking, in which an attacker takes over an existing session and can thereby achieve remote code execution as the zammad user: executing code on the system under that account. CVE-2026-102490 then enables privilege escalation, from the local zammad user to root, the account with full rights on the system. DIVD advises affected users to upgrade to a version and configuration in which the vulnerabilities are not exploitable, including upgrading to Zammad 7 where applicable, or to take the system offline while investigating and remediating the exposure.

Why does an agentic-AI method make software vulnerabilities more dangerous?

The technical vulnerabilities have been established; the interpretation that an AI agent drove the attack comes from DIVD itself and is, in our assessment, the newsworthy point. Our reading: an agentic method does not change which flaws exist, but it does change how quickly they are exploited one after another.

Our analysis: the risk became especially serious because the two flaws could be combined into one attack chain. The value lies in the combination: taking over a session, executing code and raising privileges; from that position the attackers were, according to DIVD, able to exfiltrate data. In our analysis, an agentic method can shorten the time between those attack steps because software can proceed from one operation to the next without waiting for a human operator to enter each command. In our analysis, that can shrink the window in which a defender can intervene between discovery and full compromise. Wider reporting placed the DIVD incident in that context of agents combining smaller vulnerabilities into a serious attack. That same reporting also mentioned a new platform for AI oversight; we have found no primary source for it and therefore leave out specific product claims. In our analysis, the DIVD incident itself is the concrete reported example that makes this scenario more than hypothetical for this article.

What does this incident mean for directors, lawyers and CISOs?

Our analysis: because the attacker strung together two zero-days into session hijacking, code execution and root access, organisations with publicly reachable software face a chain risk, not merely a patch risk, because a compromise can expose the privileges and paths available to the affected service; therefore the CISO must record, per internet-facing application, which rights a compromised service account would gain and reduce that account to the minimum now. Our analysis: because DIVD reports that segmentation helped limit lateral movement, segmentation should be treated as an operational control that can help contain a compromise rather than merely as a theoretical best practice; therefore the director should give segmentation of critical systems as an explicit instruction to IT this quarterly cycle, with a report on what is not separated today. In our analysis, organisations should set an accelerated patch-or-isolate route for publicly reachable systems, with timelines based on exposure, exploitability and business impact rather than relying automatically on a weeks-long cycle; therefore the responsible manager must enforce such a route for publicly reachable systems, so that taking a system offline is a rehearsed option and not a panic decision. Because DIVD reports that the attackers could exfiltrate data from the compromised environment, the organisation must involve the lawyer and the incident team in good time in assessing which data may have been accessed and which notification and documentation obligations follow from that. In our analysis, the organisation must retain and use independent logging to reconstruct, as far as is technically possible, which data were accessed; that reconstruction can support the assessment of any GDPR notification and documentation obligations.

Which measures now belong together in one vulnerability chain?

Vulnerability management that only determines whether software has a flaw does not cover this scenario. The coherence matters. Therefore treat the following points as one chain, not as separate projects:

  • Inventory which systems are reachable from the internet and which software runs on them, including version.
  • Patch critical, internet-facing software quickly or take the system offline, as DIVD advises for Zammad.
  • Restrict the rights of service accounts, so that a hijacked session does not automatically lead to root access.
  • Enforce network segmentation between critical systems to slow lateral movement.
  • Actively monitor for indicators of compromise and retain independent, tamper-resistant logging.
  • Rehearse incident response, including deliberately taking a system offline.

Because an autonomous agent uses system rights and strings together actions, this touches on the broader shift from perimeter defence to identity and runtime. In our analysis, organisations seeking to improve post-incident reconstruction should consider audit trails that record execution and evidence separately, subject to validating that approach for their own environment. More background on this kind of attack is in our overview of agentic AI and AI agents.

Sources and references

  1. DIVD-2026-00014 - When, not if…DIVD CSIRT · 2026-10-01
  2. DIVD-2026-00015 - Vulnerabilities in Zammad during investigation of case DIVD-2026-00014DIVD CSIRT · 2026-10-01
  3. Kort: Agents vergroten risico sw-kwetsbaarheden, SAS lanceert platform ai-toezicht (en meer)Computable · 2026-10-07

Sources: The article relies on the primary case reports from DIVD CSIRT about the breach and the Zammad vulnerabilities, with context from reporting by Computable.

← All articles in this topic ← All articles