The Dutch Institute for Vulnerability Disclosure (DIVD) recently encountered a sophisticated cyber attack leveraging artificial intelligence to exploit two undisclosed vulnerabilities in the Zammad support platform. This breach, which took place on September 21, prompted DIVD to initiate a comprehensive incident response, temporarily suspending access to its systems while they investigated the intrusion.
Details of the Cyber Attack
In a LinkedIn update dated September 24, DIVD characterized the attack as unique due to its AI-driven nature. The organization’s investigation revealed that the cybercriminals exploited two specific zero-day vulnerabilities in the Zammad system, which they detailed on September 30. The initial flaw, identified as CVE-2026-102489 with a critical CVSS score of 9.4, allowed unauthorized attackers to execute remote code and access user sessions.
The second vulnerability, CVE-2026-102490, also scored at 9.4 on the CVSS scale, enabling local users to elevate their privileges to root. When combined, these vulnerabilities facilitated the attackers’ ability to manipulate sessions, execute remote code, and escalate privileges rapidly, all due to the AI components of the attack.
Impact and Mitigation Efforts
The attackers managed to move laterally from the compromised Zammad instance, targeting additional services and extracting data. However, DIVD’s network segmentation efforts successfully limited the attackers’ reach within the environment. The organization continues to investigate potential signs of compromise and considers any unauthorized access a serious breach until proven otherwise. DIVD regards halting the attack as a significant victory in their ongoing cybersecurity efforts.
Following the identification of these vulnerabilities, DIVD promptly reported them to Zammad. The company is actively working on remedies for these security issues. Affected versions include Zammad 6.3.0 to 6.5.4, with versions 7.0.0 to 7.1.3 also affected but less susceptible to exploitation due to specific environmental conditions.
Recommendations and Future Outlook
DIVD strongly recommends that Zammad users upgrade to version 7 or temporarily disable the system to mitigate potential risks. To support organizations in identifying potential compromises, DIVD has released a verification script and is actively scanning for vulnerable Zammad instances, notifying their respective administrators.
As cyber threats evolve, this incident underscores the importance of robust security measures and timely updates. Organizations are urged to remain vigilant and proactive in addressing vulnerabilities to protect against similar sophisticated attacks in the future.
