Two critical vulnerabilities were discovered in Zammad ticketing software: CVE-2026-102489 enables remote code execution through session hijacking in versions 6.3.0–6.5.4 and 7.0.0–7.1.3, while CVE-2026-102490 allows local privilege escalation to root in all versions. DIVD is actively scanning for vulnerable instances and alerting administrators to upgrade or take systems offline.
The Dutch Institute for Vulnerability Disclosure was breached on September 21 by an automated AI agent that exploited two zero-day vulnerabilities in their Zammad helpdesk software. The attacker used session hijacking and privilege escalation to gain root access, but network segmentation limited further damage; DIVD disclosed the breach three days later and has not yet identified the threat actor.