Two critical vulnerabilities were discovered in Zammad ticketing software: CVE-2026-102489 enables remote code execution through session hijacking in versions 6.3.0–6.5.4 and 7.0.0–7.1.3, while CVE-2026-102490 allows local privilege escalation to root in all versions. DIVD is actively scanning for vulnerable instances and alerting administrators to upgrade or take systems offline.
The Dutch Institute for Vulnerability Disclosure was breached on September 21 by an automated AI agent that exploited two zero-day vulnerabilities in their Zammad helpdesk software. The attacker used session hijacking and privilege escalation to gain root access, but network segmentation limited further damage; DIVD disclosed the breach three days later and has not yet identified the threat actor.
Dutch cybersecurity organization DIVD announced it was hacked after detecting suspicious activity, with preliminary investigation suggesting an AI-powered attack. The organization is conducting forensics with third-party assistance, has notified relevant authorities including the Dutch data protection and cybersecurity agencies, and is treating the incident as a potential breach while maintaining isolated infrastructure.