TL;DR
Attackers chained two Zammad zero-day flaws to break into the Dutch Institute for Vulnerability Disclosure (DIVD) on September 21. The pair, CVE-2026-102489 and CVE-2026-102490, took the intruders from a hijacked session to root in seconds. DIVD says the attack looked like the work of an agentic AI, and it urges every Zammad user to upgrade to version 7 or take the system offline.
- Product: Zammad GmbH Zammad
- Vulnerabilities: 2 flaws (CVE-2026-102489, CVE-2026-102490)
- Highest severity: 9.4 (Critical · CVSSv4)
- Worst impact: Undisclosed RCE in v6.3 and higher
- Status: Exploited in the wild
- Action: Update to 6.5.4, 7.0.0, 7.1.0-alpha now
| CVE | CVSS (CVSSv4) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-102489 | 9.4 | Undisclosed RCE in v6.3 and higher | 6.5.4, 7.0.0 | Exploited in the wild |
| CVE-2026-102490 | 9.4 | Undisclosed LPE in v1.5.0 to v7.1.0-alpha | 7.1.0-alpha | Exploited in the wild |
Route critical CVEs to one Slack channel, everything else to another.
Try Team free for 14 daysWhy It Matters
Zammad is an open-source helpdesk and ticketing platform. Teams use it to handle support email, chats, and customer data. As a result, a compromised Zammad server can expose sensitive tickets and give attackers a path into the wider network.
These are confirmed in-the-wild exploits, not lab findings. Both CVE records carry the CVSS 4.0 “Attacked” exploit maturity flag. Moreover, DIVD itself was the victim. Its incident case DIVD-2026-00014 states that the attackers “got in through two zero-days in Zammad that together allowed session hijacking, remote code execution and privilege escalation from the Zammad user to root.”
DIVD has also labeled the pair “known exploited vulnerabilities.” It is now scanning the internet for exposed Zammad servers and warning their owners.
An AI-Driven Attack
The way the attack unfolded stands out. DIVD says “the modus operandi indicates an agentic AI powered attack, something we had not seen before.” Log files showed the attacker’s scripts held notes in which the agent justified its own actions. According to DIVD, a human attacker “wouldn’t bother with” such comments.
The intrusion was fast but messy. DIVD describes an agent “deciding each next step itself at speed on sloppy logic.” Its overexplaining notes later made reverse engineering easier. DIVD found no link to any known threat actor.
Network segmentation helped limit the damage. Still, the attackers stole volunteer data, including DIVD email addresses and possibly contact details. DIVD warns that this makes it easier for someone to pose as a volunteer.
Timeline
- September 21: The attacker first accesses DIVD systems.
- September 22: DIVD detects the activity, blocks access, and starts forensics with Merlon Security.
- September 24: DIVD reports both flaws to Zammad.
- September 26: DIVD begins scanning for exposed instances and notifying owners.
- September 30: DIVD publicly names Zammad as the entry point.
How the Attack Works
CVE-2026-102489: Session Hijack to RCE
The first Zammad zero-day is a session hijack flaw. It leads to remote code execution as the zammad system user. The CVE record lists a CVSS 4.0 score of 8.7. No privileges are needed, though some passive user interaction is required. DIVD has not released further technical details.
CVE-2026-102490: Local Privilege Escalation to Root
The second flaw lets the local zammad user escalate to root. On its own, it scores 8.5 because it needs local access. However, it fits neatly after the first bug.
The Chain
Together, the two flaws give an unauthenticated network attacker full control of the server. Both CVE records rate the chained attack 9.4, which is Critical. The records also mark the chain as automatable. That matches DIVD’s account of an agent that reached root in seconds.
Affected Versions
- CVE-2026-102489: Zammad 6.3.0 to 6.5.4 is exploitable.
- CVE-2026-102489: Zammad 7.0.0 to 7.1.3 contains the bug, but DIVD says it is “not exploitable due to environment conditions.”
- CVE-2026-102490: Zammad 1.5.0 up to the 7.1.0 alpha, which covers nearly every release.
Both flaws affect Linux and Docker deployments.
Patch and Mitigation Steps
Upgrade or Go Offline
DIVD’s Zammad vulnerability case DIVD-2026-00015 gives clear advice. Users should “upgrade to version 7 of Zammad or to take it offline.” Version 7 blocks the remote entry point. That cuts off the known chain.
Note that the root escalation bug still affects current releases. DIVD says Zammad is working on a fix. Admins should therefore watch for a new release and apply it quickly.
Check for Compromise
- Run DIVD’s log check script against your Zammad logs to look for indicators of compromise.
- Remove internet access to Zammad where you can, or place it behind a VPN.
- Rotate credentials stored on or reachable from the Zammad server.
- Segment the helpdesk server from other critical systems.
This Zammad zero-day chain shows how fast AI-driven attacks can move. Organizations running older Zammad builds should treat this as urgent.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!