Skip to main content
Emerging ThreatsMalware & Ransomware

Zero-days in Zammad ticketing system enable AI-driven network breach

Blurred laptop screen and paperwork on a workstation in a neutral office setting.

“Used together, they allowed the attackers to hijack sessions, run code remotely, and escalate privileges from the Zammad user to root, in seconds, due to the agentic part of this hack,” DIVD says.

The two zero-days: CVE-2026-102489 and CVE-2026-102490

The Dutch Institute for Vulnerability Disclosure (DIVD) says the breach of its network stemmed from a chain of two previously unknown vulnerabilities in the open-source Zammad ticketing system, now identified as CVE-2026-102489 and CVE-2026-102490. According to DIVD, when used together the flaws enabled session hijacking, remote code execution, and escalation to root privileges — a combination that allowed an attacker to move from a Zammad user context to full control of a host.

An autonomous AI agent that left a clear trail

DIVD described the intrusion as “loud and very, very messy,” and importantly, the nonprofit says the attacker’s toolset included an AI agent that operated without external direction. That agent moved autonomously and decided its next steps on its own; DIVD recovered extensive details because the agent “left behind clear explanations of its decisions,” enabling the organization to reconstruct the incident.

Rapid lateral activity and what the attacker accessed

After exploiting the Zammad flaws, the threat actor used the foothold to access other services and to read and exfiltrate data from DIVD’s systems. DIVD emphasizes that these actions were performed in a matter of seconds, a speed the organization attributes to AI automation. Despite that rapid activity, DIVD reports that due to network segmentation and incident response actions the attacker did not move deeper into the network. The investigation remains ongoing and DIVD has promised to share additional updates tomorrow.

Zammad’s role and the vendor footprint

Zammad is described in the release as an open-source, AI-powered helpdesk and support ticketing platform used for customer inquiries, IT support requests, and internal ticketing. The product is available as either a self-hosted or hosted service; Zammad itself claims on its website to have over 2,000 customers and 55,000 users, including De’Longhi, Amnesty International, and NextCloud. DIVD discovered the vulnerabilities in collaboration with Merlon Security and notified Zammad while also alerting other users of vulnerable instances.

Recommended mitigation: upgrade or take instances offline

DIVD recommends that Zammad users upgrade to version 7, which the nonprofit considers safe, or take affected instances offline as soon as possible. That guidance follows the coordinated discovery and notification process DIVD carried out with Merlon Security and reflects DIVD’s assessment of the immediate technical risk posed by the two zero-days combined with agentic AI automation.

What this means for Zammad users, open-source maintainers, and security teams

  • Zammad users: Operators of self-hosted Zammad instances are urged to upgrade to version 7 or to disconnect vulnerable deployments immediately, because DIVD says the combined vulnerabilities enable session hijacking, remote code execution, and privilege escalation to root.
  • Open-source maintainers: The incident underlines the value of coordinated discovery and notification; DIVD worked with Merlon Security and notified Zammad before alerting other users, and DIVD plans to release further findings tomorrow.
  • Security teams and incident responders: DIVD’s account shows that network segmentation and prompt incident response actions can limit deeper compromise even when attackers move “in seconds” with AI assistance, but the speed and autonomy described raise new challenges for containment and forensic reconstruction.

DIVD’s account is concise but direct: two chained zero-days in a widely used helpdesk platform, combined with an autonomous AI agent, produced a fast, noisy intrusion that was reconstructible because the agent left explanatory artifacts. The next steps named by DIVD are concrete — upgrade to Zammad 7 or take instances offline — and the organization has signaled it will provide more detail tomorrow. For operators running Zammad instances, that imminent update will be the clearest signal of remediation progress and remaining exposure.

https://www.bleepingcomputer.com/news/security/divd-says-zammad-zero-days-enabled-ai-driven-network-breach/