Two Zammad zero-days let an AI agent reach root
DIVD says two Zammad zero-days let an AI agent hijack a session, reach root, and exfiltrate data in seconds; network segmentation limited the breach.
The Dutch Institute for Vulnerability Disclosure reconstructed the attack on its own network from the attacker’s own notes. The AI agent that ran the intrusion left behind clear explanations of its decisions, step by step, so DIVD could walk back through what it did and why. That record is the unusual part. The chain underneath it is competent but not exotic.
DIVD says two zero-days in the open-source Zammad ticketing system, now tracked as CVE-2026-102489 and CVE-2026-102490, let the attacker hijack a session, run code remotely, and escalate from the Zammad service user to root. In the nonprofit’s words: “Used together, they allowed the attackers to hijack sessions, run code remotely, and escalate privileges from the Zammad user to root, in seconds, due to the agentic part of this hack.” Once at root, the agent reached other services and read and exfiltrated data from DIVD’s systems.
Speed is the point DIVD keeps returning to. Session hijack through to root to data exfiltration happened in seconds, because an agent was driving rather than a human typing commands and waiting on output. DIVD describes the attack as autonomous: the agent moved on its own and chose its next steps without external direction.
It was also, in DIVD’s description, “loud and very, very messy.” An operator pacing a manual intrusion stays quiet to avoid tripping alarms. An agent optimizing for its goal burned through the chain fast and left a trail, including the commentary that made reconstruction possible.
What stopped it was ordinary. DIVD credits network segmentation and its incident response for keeping the threat actor from moving deeper into the network. The investigation is still open.
Zammad is a self-hosted or hosted helpdesk and ticketing platform. Zammad says it has over 2,000 customers and 55,000 users, naming De’Longhi, Amnesty International, and NextCloud. DIVD found the two flaws with Merlon Security, reported them to Zammad, and is now notifying operators of vulnerable instances.
If you run Zammad, the guidance from DIVD is short: upgrade to version 7, which it considers safe, or take the instance offline until you can. In this incident the ticketing system was the way in: a hijacked session there led to root and then to other services on DIVD’s network. The segmentation around it is what kept this from being worse.
DIVD said it would publish more tomorrow.
Keep Reading
cryptocurrencyAttackers drained $387.5M through Bitget's own security appliances
Bitget confirms a third-party zero-day let attackers reach its wallet job server and drain $387.5M; SlowMist and Mandiant trace the two-stage path.
netscalerCitrix patches second NetScaler SAML bug in days
Citrix patched NetScaler zero-day CVE-2026-88779, a SAML memory overflow under active attack that causes denial-of-service and may allow code execution.
appleiOS CoreGraphics PoC published two days after the patch
Apple patched CVE-2026-86950, an out-of-bounds write in CoreGraphics triggered by a malicious PDF font and used in targeted attacks on iOS before 27.
Latest on the Wire
Full wire →- 16 Fake Firefox Extensions Stole Crypto Recovery PhrasesThe Hacker News
- AI Bolsters and Threatens Autocratic RegimesSchneier on Security
- AI Developer Launches Open-Source Adobe AlternativesArs Technica
- AI Helps Solve 15-Year Mystery of Obscure Band SalvageHacker News
New signal daily · RSS
Stay in the loop
New writing delivered when it's ready. No schedule, no spam.