DIVD Zammad breach: AI agent suspected, root flaw unpatched
The DIVD Zammad breach: two zero-days took an attacker to root in seconds, and DIVD blames an AI agent. Which versions are exposed and what admins should do.
Source-based. Written from the documents, reporting and reviews linked in the text. Nothing here was tested hands-on by The Ruling Desk. How we work

The DIVD Zammad breach began on September 21, 2026, when an attacker chained two unknown flaws in Zammad, the open-source help desk software, to break into the Dutch Institute for Vulnerability Disclosure. DIVD, a volunteer nonprofit that warns organizations about vulnerable systems, says the attack's pattern points to an autonomous AI agent rather than a person at a keyboard. Here is what DIVD has published, why it reached that conclusion, which Zammad versions are exposed, and what to do if you run one.
Key takeaways
- Two zero-days, chained: CVE-2026-102489 lets an attacker hijack sessions and run code as the Zammad user on versions 6.3.0 to 6.5.4, and CVE-2026-102490 takes that user to root. DIVD scores the chain 9.4 out of 10.
- The AI agent is DIVD's assessment: DIVD says the attack's modus operandi indicates an agentic AI attack. It has not named a model or an operator, and no outside party had confirmed it as of October 1, 2026.
- The root flaw has no patch yet: the Dutch National Cyber Security Centre (NCSC) says a fix exists for the first flaw but not the second. DIVD's advice is to upgrade to Zammad 7 or take the instance offline.
- Data was taken: DIVD confirms volunteers' DIVD email addresses, and possibly their contact details, were exfiltrated. Anyone who emailed its CSIRT team should assume the attackers may have those messages.
- Save your logs first: the NCSC asks admins to copy application and network logs before updating, and DIVD offers a script that checks Zammad logs for signs of compromise.
What happened in the DIVD Zammad breach
DIVD's incident case file lays out the timeline. The first malicious access came on Monday, September 21. DIVD spotted the activity on September 22, blocked access to every system in its data center, and opened a forensic investigation with the security firm Merlon Security.
On September 24 it went public with a blog post titled "It was a matter of when, not if", admitting that after almost seven years, "we're the hackers that got hacked." The same day it reported the flaws to Zammad and informed the Dutch data protection authority and the NCSC. It published the two CVEs on September 29.
The Zammad zero-days opened DIVD's own ticketing system. Its overview of the data investigation, updated October 1, says the attackers entered through the Zammad instance its CSIRT team uses, which holds every email sent to the CSIRT mailbox and every reply. DIVD also lists signs of compromise on its Jira and Confluence project tools and on its IT support systems, while its accounting and bank account, run by an outside party, show none so far.

Why DIVD thinks an AI agent did it
DIVD's first statement already called it "an attack we have not seen before" because of its AI-driven modus operandi. Its later statements, posted on LinkedIn and reported by BleepingComputer and Help Net Security, give three reasons:
- Speed: DIVD says the two flaws let the attacker hijack sessions, run code and climb from the Zammad user to root "in seconds."
- Mess: DIVD described the attack as "loud and very, very messy," with sloppy logic and self-inflicted errors, such as polluting its own man-in-the-middle attack with password spraying (trying common passwords across many accounts).
- A paper trail: the agent left verbose explanations of its decisions behind, which DIVD says helped it reconstruct what happened.
Those are the victim's own forensic observations. DIVD has not published the logs, named a model or said who launched the agent, so the AI attribution stays its assessment until someone else checks the evidence.
It's also not the first AI-run intrusion on record, whatever some headlines say, and DIVD doesn't claim it is. In November 2025, Anthropic reported an espionage campaign in which a group it assessed as Chinese state-sponsored used Claude Code to perform 80 to 90% of the work. What sets DIVD's case apart is that the victim is a security organization describing the attack in detail, in public. For the wider picture, see our explainer on AI security incidents at OpenAI and Anthropic.
Which Zammad versions are affected
| Flaw | What it does | Affected, per DIVD | Fix |
|---|---|---|---|
| CVE-2026-102489 | Session hijack that leads to remote code execution as the zammad user | 6.3.0 to 6.5.4 exploitable; 7.0.0 to 7.1.3 contain the bug but DIVD says it can't be exploited there | Upgrade to Zammad 7 |
| CVE-2026-102490 | Lets the local zammad user escalate to root | All versions from 1.5.0, including the latest alpha | None as of October 1, 2026 |
On its own, DIVD rates the remote code execution flaw 8.7 and the privilege escalation flaw 8.5 on the CVSS 4.0 scale, and both 9.4 when chained. The second record lists its range as 1.5.0 up to 7.1.0-alpha but describes the bug as present in all versions including the latest alpha. The NCSC alert of September 30 treats it as unpatched in all common versions, so assume yours is affected.
Zammad had not published an advisory for either CVE on its GitHub security page as of October 1. DIVD's case file for the two flaws says Zammad is working on a fix.
What Zammad admins should do now
- Check every instance's version. If any runs 6.3.0 to 6.5.4, it's in the range DIVD saw exploited.
- Copy your logs before you touch anything. The NCSC asks for application and network logs, because you may need them later to find out whether you were hit during the zero-day window.
- Run DIVD's check. The Zammad case file links a script that scans Zammad log files for DIVD's indicators of compromise.
- Upgrade to Zammad 7 or take the instance offline. That is DIVD's recommendation, and DIVD says the remote code execution flaw can't be exploited on version 7.
- Shrink exposure until the root fix ships. The NCSC suggests talking to your IT provider about the unpatched flaw. We'd add that keeping Zammad reachable only through a VPN or an internal network limits who can try the chain.
- Be wary of mail that claims to come from DIVD. DIVD warns that the leaked addresses raise the risk of someone posing as a DIVD volunteer.
DIVD says it has been scanning for exposed Zammad instances and notifying their owners since September 26. If you're patching other systems this week, our guide to the Cisco SD-WAN zero-day follows the same save-logs, check, then patch order.
What happens next
- A fix for the root flaw: Zammad has not given a date, and neither DIVD nor the NCSC lists one.
- The full data picture: DIVD's data overview marks most categories as still under investigation, and it says it will update that page as it learns more.
- Evidence for the AI claim: if DIVD publishes the agent's logs, outside researchers will be able to test its attribution. Labs are already measuring how well models write exploits, as our story on GLM-5.3's exploit tests shows.
Bottom line
The DIVD Zammad breach is a warning for every Zammad admin, so treat it as urgent: save your logs, run DIVD's check, upgrade to version 7 or take the instance offline, and keep it off the open internet until Zammad patches the root flaw. The AI agent is DIVD's assessment from its own forensics, detailed but not independently confirmed. The vulnerabilities are real either way.
FAQ
What is DIVD?
The Dutch Institute for Vulnerability Disclosure is a Dutch nonprofit run largely by volunteer researchers. It scans the internet for vulnerable systems, warns their owners, and publishes its cases and CVEs through its CSIRT team.
Is Zammad 7 safe from these flaws?
Only partly. DIVD says the remote code execution flaw is present in 7.0.0 to 7.1.3 but can't be exploited there, which is why it recommends version 7. The root escalation flaw, CVE-2026-102490, affects every version including the latest alpha and had no patch as of October 1, 2026.
Was this the first cyberattack carried out by an AI agent?
No, and DIVD doesn't say it was. Anthropic reported in November 2025 that a state-sponsored group used Claude Code to run most of an espionage campaign. DIVD's case stands out because the victim is a security organization describing the attack in public.
How do I know if my Zammad server was hacked?
DIVD publishes a log check script with its case file that scans Zammad logs for the indicators it found. Copy your application and network logs before updating, as the NCSC advises, so the evidence survives the upgrade.