Security3 publishers2 min readPublished
DIVD traces its breach to two chained zero-days in its own Zammad helpdesk
DIVD, the Dutch volunteer disclosure group, was breached through two chained zero-days in its own Zammad helpdesk that took an attacker to root in seconds. Zammad claims over 2,000 customers, and DIVD wants every older install upgraded to version 7 or taken offline.
The Watch · Security desk

What happened
- DIVD found the flaws with Merlon Security; they are tracked as CVE-2026-102489 and CVE-2026-102490 and enable session hijacking and remote code execution.
- From root, the attacker reached other DIVD services, read data and exfiltrated some of it.
- DIVD links the speed of the escalation to an AI agent that made decisions and carried out next steps without waiting for a human operator.
- DIVD is notifying owners of vulnerable instances, has published a log-check script, and says its next public statement will come on October 1.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint No patch existed when the attacker struck, so segmentation was what capped DIVD's loss; for other operators, where the helpdesk sits on the network counts alongside which version it runs.
- contradiction Security Affairs places the start of the chain both at a regular account and at unauthenticated access; if no login is needed, any reachable pre-7 instance is exposed without stolen credentials.
- capability An agent that chains flaws and escalates with no human at each step was caught here partly because it was noisy; Security Affairs says a quieter run of the same approach could be harder to detect.
Whether the chain needs a login decides how exposed other Zammad operators are, and the coverage disagrees on it. Security Affairs describes the attacker moving "from a regular Zammad account to root access" [12]. Later in the same article it says the attack runs "from unauthenticated access to root privileges within seconds" [13]. DIVD's own wording leaves the question open. "Used together, they allowed the attackers to hijack sessions, run code remotely and escalate privileges from the Zammad user to root, in seconds, due to the agentic part of this hack," the organisation wrote on LinkedIn [5]. The published accounts begin at that foothold [5][6]. They do not say how the attacker first reached the instance or who the attacker is [2][5].
Patching would not have kept the attacker out. Neither flaw was known until DIVD and Merlon Security found them while working out how the attackers had got into DIVD's systems [3][20]. DIVD has since reported them to Zammad [22]. Zammad markets the software for customer inquiries and IT support requests as well as internal ticketing [15]. A helpdesk built to take customer inquiries accepts input from outside by design, even when an organisation runs it for its own use, as DIVD did [2]. Once the attacker held root, network segmentation and a fast response from DIVD's IT and incident response teams stopped it going further [7]. DIVD said some damage had already occurred by then [8].
The evidence for the AI agent comes from the victim's reconstruction. DIVD called the attack "loud and very, very messy" [9]. The agent left clear explanations of its decisions, and DIVD used them to rebuild the sequence of events [10]. On the public record this is one intrusion at one organisation [1]. The claim that an agent drove it rests on DIVD's account [9][10].
What to watch
- DIVD's next public statement, for how the attacker first reached the Zammad instance and whether the chain requires valid credentials.
- A Zammad advisory listing affected version ranges and stating whether hosted instances were exposed or already fixed.
- Reports of CVE-2026-102489 and CVE-2026-102490 being exploited at other Zammad installations DIVD is notifying.