AI Agent Chains Zammad Zero-Days To Take Over DIVD Systems in Seconds
Brief
DIVD was breached through two Zammad zero-days that let an AI agent reach root in seconds, steal data and pivot to other services before being stopped.
The Dutch Institute for Vulnerability Disclosure, a nonprofit organization of volunteer security researchers whose whole job is finding and responsibly disclosing vulnerabilities in other people’s software, just disclosed that it got breached through two zero-days in its own ticketing system.
The attackers got in through Zammad, an open-source helpdesk platform that DIVD used internally. Working with Merlon Security, DIVD identified two previously unknown vulnerabilities, tracked as CVE-2026-102489 and CVE-2026-102490.
Each vulnerability was serious on its own, but chaining them made the attack much more dangerous.
