An AI-driven attack recently exploited critical vulnerabilities in Zammad, an open-source helpdesk platform, severely impacting the Dutch Institute for Vulnerability Disclosure (DIVD). The breach, occurring on September 21, 2026, involved an AI agent that swiftly escalated from session hijacking to obtaining root access, essentially taking over the server within moments.
DIVD’s detection efforts revealed the attack the following day, prompting immediate action to restrict access to affected systems within its data center. Initial investigations by October 1 confirmed that volunteer email addresses were compromised, with ongoing inquiries into potential exposure of additional sensitive information, such as contact details and support-related communications.
Uncovering the Attack
Sysdig researchers conducted a thorough analysis of the intrusion, noting the AI agent’s erratic and disruptive actions. The attacker’s scripts included explanatory comments, inadvertently aiding investigators in identifying the breach. This incident underscores the evolving nature of AI-assisted cyber threats, differing from traditional malware types.
While no specific human operators or groups have been linked to the DIVD breach, Sysdig compared the event to previous autonomous attacks like JADEPUFFER. These comparisons highlight AI agents’ capabilities to adapt and evolve their methods during intrusions.
Details of the Zammad Vulnerabilities
The exploit leveraged a zero-day vulnerability chain in Zammad, starting with CVE-2026-102489, which facilitated session hijacking and remote code execution as the Zammad service account. This flaw, with a severity score of 8.7, did not require prior privileges for exploitation. The vulnerability was present in versions 6.3.0 to 6.5.4, with later versions partially affected.
Another flaw, CVE-2026-102490, allowed the attacker to escalate privileges to root. Affecting versions 1.5.0 through 7.1.0-alpha, this local privilege escalation vulnerability scored an 8.5 in severity. Combined, the vulnerabilities received a critical chain score of 9.4, indicating their severe impact on system security.
Response and Mitigation Strategies
In response, Sysdig recommended upgrading to Zammad version 7.0.0 or later and taking other vulnerable installations offline. However, the local escalation issue remains a concern, necessitating further attention and mitigation. Blocking the initial entry point alone does not guarantee system security.
Effective defense strategies include isolating helpdesk infrastructures, restricting access to internal services, and limiting outgoing traffic. Sysdig also advises preserving logs and monitoring service accounts for unusual activity, such as unexpected command execution and unauthorized access attempts.
The rapid escalation to root access demonstrated by the AI agent highlights the need for automated containment measures for prompt response to reliable alerts. As DIVD continues its investigation into the breach, the potential risks of impersonation using stolen volunteer addresses remain a significant concern.
