Organizations/platform

Zammad

Open-source helpdesk and ticketing software.

1 records1 attackWebsite
Sep 24, 2026
DIVD says an agentic attack breached it through two Zammad zero-days and compromised some of its data
AttackIncidentDutch Institute for Vulnerability Disclosure (DIVD), Zammad, Merlon Security

On 2026-09-24 the Dutch Institute for Vulnerability Disclosure (DIVD) said it had been hacked and that the attack's modus operandi indicated agentic AI. DIVD's case pages, last modified 2026-10-01, say first access was on 2026-09-21 through two previously unknown vulnerabilities in the Zammad ticketing system (CVE-2026-102489 and CVE-2026-102490) and that DIVD "got hacked through AI agents"; press reports quote DIVD as saying the two flaws let the attacker hijack sessions, run code and reach root "in seconds, due to the agentic part of this hack". DIVD's separate data overview says the attackers got in through the ticketing system its CSIRT team uses, that data was compromised and possibly exfiltrated, and that extraction was difficult for them. DIVD reported the flaws to Zammad on 2026-09-24 and advises upgrading to Zammad 7; the agentic characterization is DIVD's own assessment and its investigation is open.