Zammad Zero-Days Hit CISA KEV After an AI Agent Rooted DIVD's Helpdesk in Seconds
🛡️ Security •

Zammad Zero-Days Hit CISA KEV After an AI Agent Rooted DIVD's Helpdesk in Seconds

An AI agent chained a session-fixation flaw and a local root escalation in Zammad to breach DIVD in seconds. Both CVEs are in CISA KEV with a 5 October deadline; the vendor disputes the disclosure.

zammadcve-2026-102489cve-2026-102490divdcisa kev

The Dutch Institute for VulnerabilityVulnerability🛡️A weakness in software, hardware, or processes that can be exploited by attackers to gain unauthorized access or cause harm. Disclosure spends its time telling other organisations their systems are exposed. On 21 September 2026 it was on the receiving end: an attacker that DIVD describes as an autonomous AI agent chained two previously unknown flaws in the organisation's self-hosted Zammad helpdesk, hijacked a session, ran code as the Zammad service user, and escalated to root. DIVD says the whole sequence took seconds. On 2 October CISA added both flaws, CVE-2026-102489 and CVE-2026-102490, to the Known Exploited Vulnerabilities catalogue with a remediation deadline of 5 October. Zammad, the vendor, has publicly disputed how the case was disclosed and only received technical details of the second flaw on the evening of 1 October.

What Happened

DIVD detected suspicious activity on 22 September, a day after initial access, blocked access to its datacentre, and brought in third-party forensic specialists. Its first suspicion fell on Citrix NetScaler, which was being exploited across the industry that same week, but the forensic trail led instead to Zammad, the open-source ticketing system DIVD uses internally. Working with Merlon Security, DIVD's team reproduced the exploitExploit🛡️Code or technique that takes advantage of a vulnerability to cause unintended behavior, such as gaining unauthorized access. on 22 and 23 September and reported it to Zammad on 24 September. Two days later DIVD began scanning the internet for vulnerable instances and notifying their owners, and on 29 September it published CVE records for both flaws through its own CVE Numbering Authority.

The attacker's behaviour is the most unusual part of the story. DIVD describes the intrusion as "loud and very, very messy" and attributes it to agentic AI software that chose its own next steps without human direction. The agent left behind notes in which it justified its own actions, explaining why what it was doing was acceptable. That running commentary, atypical of a human intruder, is what let DIVD reconstruct the attack in detail. The attacker pivoted to other services and exfiltrated data before being cut off. DIVD says network segmentationNetwork Segmentation🛡️Dividing a network into isolated zones with controlled traffic between them so that a compromise in one zone, such as a helpdesk segment, cannot reach systems in another without crossing an enforced boundary. and a fast response stopped the intrusion from reaching deeper systems, but acknowledges that volunteer email addresses and possibly contact details were taken, which raises the risk of impersonation attempts against people who work with DIVD.

Who Is Affected

Zammad is a widely deployed open-source helpdesk. BleepingComputer puts its footprint at roughly 2,000 customers and 55,000 users, including De'Longhi, Amnesty International and Nextcloud. Anyone running a self-hosted instance reachable from the internet should treat this as urgent, and the version picture is unusually tangled, so read it carefully.

CVE-2026-102489 is the remote half of the chain. DIVD's record says Zammad 6.3.0 through 6.5.4 are exploitable, and that the same flawed code is present in 7.0.0 through 7.1.3 but cannot be exploited in practice because of the runtime environment those versions use. NVD's configuration data lists both ranges as vulnerable. Zammad's statement draws a sharper line: 6.5 and older are affected and have been out of support for some time, 7.0 and later are not affected, and the code was nonetheless hardened in 7.2.0, released on 23 September. Zammad also says it first received a report about this issue in August 2026 and analysed it then, which predates the DIVD timeline. Which organisation reported it in August is not stated.

CVE-2026-102490 is the local privilege escalationPrivilege Escalation🛡️An attack technique where an adversary gains elevated access rights beyond what was initially granted.. DIVD says it affects every Zammad release from 1.5.0 through the 7.1.0 alpha, and NVD's description says all versions including the latest alpha allow the local zammad user to become root. Zammad's position as of 1 October midday was that it had received no technical details, could not confirm the flaw, its scope or the affected versions, and had formally asked DIVD for the information. By 19:48 that evening a Zammad developer posted that the details had arrived, that the team was working on it, and that the flaw cannot be exploited remotely on its own because an attacker would already need access to the server. No fix for the privilege escalation had been announced at the time of writing.

Technical Analysis

The first flaw is classified as CWE-384, session fixationSession Fixation🛡️An attack where the attacker knows or sets a victim's session identifier in advance, then rides that session to gain access once it becomes privileged. It works when a program uses predictable session IDs or fails to regenerate them after login., and CISA names it the "Zammad Session Fixation Vulnerability". The public records say it enables session hijackingSession Hijacking🛡️An attack where an adversary takes over a legitimate user session by stealing or predicting session tokens, gaining unauthorized access to systems or data. that leads to remote code execution as the zammad service user. The mechanics beyond that remain undisclosed, which is why the primer on how session fixation lets an attacker ride a victim's login into code execution is worth reading now: the pattern is generic to web applications and the defences do not depend on Zammad specifics.

The second flaw, CWE-269 improper privilege management, turns the service accountService Account🛡️A non-human operating system or application account under which a service runs. Its permissions define the blast radius of any exploit against that service, since attacker code executes with the service account's access to files, secrets, and the network. into root. CISA's own Stakeholder-Specific Vulnerability Categorization marks it as actively exploitedActively Exploited🛡️A vulnerability that attackers are currently using in real-world attacks, requiring immediate patching regardless of severity score. but not automatable, in contrast to the session flaw, which it rates as automatable. That matches the vendor's point that the escalation needs a foothold first. It also matches the attack as observed: the chain only works because the helpdesk's service account could reach root at all.

The scoring reflects the same split. DIVD, as the issuing CNA, scores the flaws under CVSS 4.0 at 8.7 and 8.5 standalone, and 9.4 when chained. NVD's independent CVSS 3.1 assessment gives both a 9.8. Several secondary outlets have reported the chained 9.4 as if it applied to each flaw on its own. Use the DIVD and NVD figures.

Immediate Actions

Start with inventory. Zammad instances are easy to miss because helpdesks are often owned by a support team rather than infrastructure. runZero has published a fingerprint for its service inventory that matches Zammad by the MurmurHash3 value of its favicon, which is a quick way to find instances you did not know about.

Upgrade or disconnect. DIVD's recommendation is to move to version 7 or take systems offline. Zammad's is to update to 7.2.0, the current stable release, and to treat 6.5 and older as unsupported. Given that the privilege-escalation flaw is unfixed and the vendor is still analysing it, 7.2.0 is the sensible floor, but it is not a complete fix.

Assume compromise until shown otherwise. DIVD has published a log-checking script on its CSIRT site for investigating instances. Sysdig's detection guidance focuses on behaviour that should never come from a helpdesk application: the zammad user spawning interactive shells, downloading tools, making setuid-family calls, producing root-owned child processes under the application tree, writing to privileged paths, sweeping the filesystem with find or grep, or reading database credentials and mail tokens. Preserve the Zammad and nginx logs before any rebuild. Any confirmed sign of exploitation means the host is fully compromised, so rotate every credential it held or could reach.

Then fence the account. The practical guide on how to fence in a web app's service account so a compromise stops short of root covers the controls that would have stopped this chain at step one: a service user with no path to root, default-deny egress from the helpdesk segment, and secrets scoped to what the application needs.

CISA's KEV entry flags both CVEs for forensic triageForensic Triage🛡️A rapid, structured assessment of whether a system was compromised, performed alongside patching rather than after it. It prioritizes evidence the attacker could not have altered, such as network egress and authentication logs on other systems, over the affected host's own logs. under BOD 26-04BOD 26-04🛡️CISA Binding Operational Directive 26-04, issued 10 June 2026, which replaced BOD 22-01. It assigns federal civilian agencies remediation deadlines of 3, 14, or 60 days based on asset exposure, KEV status, exploit automation, and post-exploitation impact, and requires forensic triage for the 3-day tier., so federal agencies must do that investigation, not just patch, by 5 October.

Long-Term Outlook

Two threads will outlast the patching cycle. The first is the disclosure dispute. Zammad argues that a two-day gap between vendor notification and public scanning, plus a CVE published for a flaw it had not been shown, left administrators worried and without the information they needed. DIVD was itself the victim, was watching active exploitation, and chose to warn the internet quickly. Both positions are defensible, and the practical lesson for administrators is that when a vendor says "unconfirmed" and the KEV catalogue says "exploited", the KEV entry sets your deadline.

The second is the attacker. DIVD's account is one of the first detailed descriptions of an autonomous AI agent conducting a full intrusion chain against a real organisation. It was sloppy, noisy and self-documenting, and it still got root in seconds. The strategic piece on why an autonomous AI attacker collapses your detection window to seconds works through what that means for teams whose playbooks assume a human on the other end. Zammad has promised verified results once its analysis of the privilege escalation is complete, and DIVD has promised a fuller incident report. Expect both within days, and expect the affected-version list to change.

Sources

  • CISA KEVCISA KEV🛡️The Known Exploited Vulnerabilities catalog maintained by CISA, listing vulnerabilities actively exploited in attacks that federal agencies must patch by specific deadlines. JSON feed, catalogue version 2026.10.02 (entries for CVE-2026-102489 and CVE-2026-102490): https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
  • NVD, CVE-2026-102489: https://nvd.nist.gov/vuln/detail/CVE-2026-102489
  • NVD, CVE-2026-102490: https://nvd.nist.gov/vuln/detail/CVE-2026-102490
  • DIVD CSIRT, case DIVD-2026-00015: https://csirt.divd.nl/cases/DIVD-2026-00015/
  • DIVD CSIRT, case DIVD-2026-00014 (the breach): https://csirt.divd.nl/cases/DIVD-2026-00014/
  • DIVD CVE records: https://csirt.divd.nl/cves/CVE-2026-102489/ and https://csirt.divd.nl/cves/CVE-2026-102490/
  • Zammad statement and follow-up, Zammad community forum, 1 October 2026: https://community.zammad.org/t/take-care-local-privilege-escalation-cve-2026-102490-is-reported-as-being-actively-exploited/21297
  • Zammad releases page (7.2 released 23 September 2026): https://zammad.com/en/product/releases/
  • BleepingComputer, "DIVD says Zammad zero-days enabled AI-driven network breach": https://www.bleepingcomputer.com/news/security/divd-says-zammad-zero-days-enabled-ai-driven-network-breach/
  • SecurityWeek, "Zammad Zero-Days Exploited in AI-Powered DIVD Hack": https://www.securityweek.com/zammad-zero-days-exploited-in-ai-powered-divd-hack/
  • runZero, "Zammad vulnerabilities: Find impacted installations": https://www.runzero.com/blog/zammad/
  • Sysdig, "AI agent exploits Zammad zero-days in DIVD breach": https://webflow.sysdig.com/blog/ai-agent-exploits-zammad-zero-days-in-divd-breach-what-we-know-and-how-to-detect-it