Zammad Zero-Day Chain: An AI Agent Breaches DIVD

Authors: Cloud Security Alliance AI Safety Initiative
Published: 2026-10-03

Categories: Threat Intelligence
Download PDF

Zammad Zero-Day Chain: An AI Agent Breaches DIVD

Key Takeaways

The Dutch Institute for Vulnerability Disclosure (DIVD) reported that attackers compromised its systems beginning September 21, 2026 by chaining two previously unknown vulnerabilities in the open-source Zammad helpdesk platform, CVE-2026-102489 and CVE-2026-102490, and that the intrusion bore the marks of an autonomous AI agent [1][2]. DIVD’s characterization is an assessment drawn from observed behavior, not a confirmed attribution, and no actor or model has been identified publicly [3].

In our assessment, the case matters less for the vulnerabilities themselves than for what the intrusion suggests about attacker tempo. DIVD reports that the move from session hijacking to remote code execution to root took seconds [2], which compresses the window in which a human defender can notice and respond. Defenders who rely on human review before containment may be unable to respond within a window this short.

The agent’s operation was also untidy, by DIVD’s account. It ran password spraying concurrently with its man-in-the-middle attempt, which interfered with that attempt, and it left explanatory comments in its scripts [1][2]. These traits aided forensics here, but they should not be read as a durable defender advantage, since they describe one operation rather than the capability class.

Organizations running Zammad 6.3.0 through 6.5.4 should upgrade to version 7 or take the instance offline, and should assume that any internet-facing helpdesk, ticketing, or similar self-hosted application is a plausible first foothold for machine-speed attack chains [2].

Background

DIVD is a Dutch volunteer-run nonprofit that scans the internet for vulnerable systems and notifies the affected organizations. It opened two linked cases following the incident: DIVD-2026-00014 for the incident itself and DIVD-2026-00015 for the vulnerabilities discovered during the investigation and the resulting victim notification effort [1][2].

Zammad is an open-source ticketing and customer-support platform that organizations commonly self-host. According to DIVD, the two flaws were found while it investigated its own breach, with help from the incident response firm Merlon Security [2][4]. CVE-2026-102489 is described as a session hijack vulnerability leading to remote code execution as the zammad service user. It affects Zammad 6.3.0 through 6.5.4. Versions 7.0.0 through 7.1.3 contain the flaw but, per DIVD, environmental conditions prevent exploitation; DIVD does not describe those releases as fixed [2]. CVE-2026-102490 is a local privilege escalation that lets the zammad user become root and is reported to affect all versions from 1.5.0 through 7.1.0-alpha [2]. Sysdig’s analysis lists CVSS scores of 8.7 for the first flaw and 8.5 for the second, together with a combined chain rating of 9.4 that Sysdig assigns itself [3]. At the time of writing we could not locate these identifiers in the CVE record or in Zammad’s advisory archive; the identifiers and scores in this note are as reported by DIVD and Sysdig.

The reported timeline is short. Per DIVD, exploitation occurred on September 21, the team reproduced and analyzed the flaws on September 22–23, the vendor was notified on September 24, and public scanning, limited disclosure, and victim notification began on September 26 [2]. DIVD’s case page showed the matter still open as of October 1, with patches available [2]. Press coverage, including The Hacker News and SC Media, relayed DIVD’s statements [5][6]; some vendor commentary went further, calling this the first fully autonomous AI-agent attack, a claim that comes from the commentators and not from DIVD [7]. CSA has itself published an analysis of the July 2026 Hugging Face incident, which it describes as the first publicly documented fully autonomous AI attack, so “first” claims in this area should be read with that earlier record in mind [13].

Security Analysis

What DIVD Observed and What It Inferred

The factual core is narrow. DIVD observed a chain of two zero-day exploits, root access obtained quickly, data theft, and access to other services. It reports that segmentation and its incident response limited the intrusion; the public record does not show whether the attackers attempted lateral movement and were blocked or never attempted it [1][2]. The data confirmed as exposed includes volunteers’ DIVD email addresses and possibly contact details, which DIVD flagged as raising impersonation risk; the full scope of what was taken was still being assessed [1].

The AI-agent conclusion is an inference from behavior. DIVD said it could see the agent working automatically, because after each action it chose the next step itself, “at the speed of light” but with sloppy logic [5]. Its scripts contained notes in which the agent justified its own actions, and it took steps that undermined its own operation, such as mixing password spraying into its man-in-the-middle attack [1][5]. Those observations are consistent with an LLM-driven agent but do not prove one. A scripted toolkit with an error-prone operator could produce some of the same patterns, though self-explanatory comments and non-deterministic next-step selection point toward an agent. Readers should treat the claim as a plausible assessment consistent with the observed behavior, not an established fact.

Where the Agent Sat in the Chain

A point of confusion in early coverage is whether the agent found the zero-days or merely used them. Public reporting does not establish this. The Hacker News summary and Sysdig’s write-up describe the agent as executing the chain and post-exploitation activity, and a syndicated summary of BleepingComputer’s reporting says the actor exploited an undisclosed vulnerability and then used an agent for follow-up actions [3][5][8]. DIVD states the CVEs were identified during its own investigation, so we do not know whether the attacker discovered them with AI assistance, bought them, or developed them by conventional means. We did not find published exploitation details as of October 3. The title of this note refers to agent-orchestrated chaining because the reported speed and decision pattern concern the sequencing of exploits, not necessarily their discovery.

This distinction shapes the defensive reading. If the agent only sequenced known primitives, the risk is mainly one of tempo: initial access, escalation, credential attacks, and exfiltration collapse into a window shorter than a human triage cycle. If the agent also helped discover the flaws, the risk extends to the economics of vulnerability research. CSA’s earlier analysis of an AI agent finding 21 FFmpeg zero-days for $1,000 describes that second trajectory, in which discovery cost falls and the bottleneck moves to remediation [9]. The Zammad case does not show that trajectory in action, but it arrives in a period when the evidence for it is accumulating.

Why the Chain Worked

Both flaws are of a kind that defenders have long treated as individually manageable. A web-application session flaw yielding code execution as a service user is a routine initial-access path, and a local privilege escalation from a service account to root is a standard second step. Their value to an attacker came from combination. The first gave a foothold with the service account’s privileges, and the second, which per DIVD affects a very wide range of versions, converted that foothold into full host control [2]. A similar pattern appears in CSA’s analysis of the SonicWall SMA 1000 zero-days, where an unauthenticated request-forgery flaw was chained with a code injection flaw to reach root on an edge appliance [10]. In both cases the chain, not either component, determined severity.

Sysdig’s detection guidance follows from this structure: alert on shells spawned by application processes, on service accounts escalating to root through setuid calls, and on unfamiliar outbound connections from helpdesk network segments, and favor behavioral detection that does not depend on a CVE signature [3]. Such controls matter because a signature for a previously unknown flaw does not exist until after exploitation.

Observations Table

The table below separates what DIVD reported from what is inference or third-party claim.

Dimension Reported by DIVD Inference or third-party claim
Initial access Session hijack leading to code execution as zammad user (CVE-2026-102489) [2] Exact mechanism not found in published sources as of October 3
Escalation Local privilege escalation to root (CVE-2026-102490) [2] Combined CVSS 9.4 is Sysdig’s figure [3]
Speed Root “in seconds” [1][2] Consistent with automation, scripted or agentic; speed alone does not distinguish the two
Agent involvement Scripts with self-justifying notes; next-step selection after each action [1][5] “First fully autonomous AI attack” is vendor commentary [7]
Impact Volunteer emails, possible contact data; DIVD reports segmentation limited spread [1] Ticketing and project data exposed per Sysdig [3]
Actor Not identified No claim of responsibility as of Sysdig’s publication [3]

Recommendations

Immediate Actions

Organizations running Zammad should identify every instance, including internal and test deployments, and upgrade to version 7 or take the instance offline, as DIVD advises [2]. DIVD does not name a minimum fixed release, and it reports 7.0.0 through 7.1.3 as non-exploitable rather than fixed, so operators should confirm the current patched release against the vendor’s advisory before treating an upgrade as complete. DIVD also provides a log-checking script for indicators of compromise, which should be run against any instance in the 6.3.0–6.5.4 range [2]. Because CVE-2026-102490 is reported to span versions back to 1.5.0, operators of older releases should not assume that being outside the remote-code-execution range means being safe from escalation [2]. Where compromise is plausible, preserve logs for forensics and rotate every credential the host could reach, including API tokens, email integration credentials, and database secrets [3]. Staff whose addresses may have been exposed in the DIVD breach should be alert to impersonation, and recipients of unusual messages purporting to come from DIVD can verify them at the address DIVD published [1].

Short-Term Mitigations

Helpdesk and ticketing systems often hold customer data and integration credentials while sitting close to email and identity infrastructure, so they warrant segmentation comparable to that of other high-value assets. A default-deny egress policy for the helpdesk segment would constrain both data exfiltration and any agent callbacks; DIVD reports that segmentation helped limit its own incident, though the record does not show whether it was tested [1][3]. Detection engineering should target behaviors instead of CVE identifiers: application processes spawning shells, setuid-based escalation from service accounts, and anomalous outbound connections [3]. Teams should also review whether containment for high-fidelity alerts can be pre-authorized, such as isolating a host automatically when a service account gains root, since a response measured in minutes is slower than an intrusion measured in seconds [3]. Organizations that depend on open-source infrastructure may shorten notification latency by subscribing to the project’s security advisory feed and to disclosure coordinators such as DIVD.

Strategic Considerations

The more durable lesson concerns the assumptions behind existing response processes. Many playbooks assume a human adversary pausing between actions, which leaves room for analysts to correlate signals and escalate. An agent that selects its next step after each result may leave less of that room, even if its execution is imperfect. Defenders should therefore measure mean time to contain, not only mean time to detect, and test whether automated containment is acceptable for the highest-confidence detections. Privilege hygiene belongs in the same conversation: service accounts with minimal rights, hardened hosts that reduce local escalation paths, and short-lived credentials limit what a fast-moving chain can reach. Finally, organizations should resist drawing strong conclusions about attacker capability from a single incident. The reported messiness of this agent suggests current agentic tooling is imperfect, but the trajectory documented in other CSA work on AI-assisted vulnerability discovery argues for planning around more capable successors [9].

CSA Resource Alignment

CSA’s research note on the SonicWall SMA 1000 zero-days is the closest prior analysis of a chained, actively exploited pair of zero-days leading to unauthenticated root [10]. Its guidance on treating chain-level severity as the unit of risk, hunting for post-exploitation persistence, and not trusting patch status alone applies directly to the Zammad case. Zammad’s escalation step, like the SonicWall chain, shows how two moderate-looking flaws combine into a critical outcome.

CSA’s note AI Finds 21 FFmpeg Zero-Days for $1,000 examines how commodity AI agents lower the cost of vulnerability discovery and shift the pressure toward remediation speed [9]. The DIVD incident does not show an agent discovering these flaws, but it reinforces that note’s argument that remediation and containment capacity, not discovery, are the constrained resources for defenders.

On the agentic dimension of the attacker, CSA’s analysis of Hugging Face’s autonomous AI agent breach is the closest incident precedent, a production breach driven end to end by an autonomous agent [13]. CSA’s Autonomous Agentic AI Adversaries paper supplies threat intelligence and defensive guidance on such adversaries [14]. CSA’s MAESTRO agentic AI threat modeling framework provides a layered way to reason about autonomous systems, and it can be applied to adversary agents as well as to organizations’ own deployments [11]. The AI Controls Matrix v1.1 is the relevant control reference for the defensive actions above, particularly its Threat and Vulnerability Management, Infrastructure Security, and Logging and Monitoring domains [12].

References

[1] DIVD. “DIVD-2026-00014: Incident case.” DIVD CSIRT, accessed October 3, 2026.

[2] DIVD. “DIVD-2026-00015: Zammad vulnerabilities case.” DIVD CSIRT, accessed October 3, 2026.

[3] Sysdig. “AI agent exploits Zammad zero-days in DIVD breach: What we know and how to detect it.” Sysdig, September–October 2026.

[4] DEV Community. “Two Zammad Zero-Days: DIVD Reports Session Compromise, Root Access, and Data Theft.” DEV Community, 2026.

[5] The Hacker News. “ThreatsDay: AI-Powered Zero-Day Chain.” The Hacker News, October 1, 2026.

[6] SC Media. “AI agent exploits zero-day flaws in Zammad ticketing system.” SC Media, 2026.

[7] Aviatrix. “DIVD Zammad Zero-Day Breach: First Autonomous AI Agent Attack 2026.” Aviatrix, 2026.

[8] Hendry Adrian. “Automated AI agent used to breach cybersecurity nonprofit DIVD.” Syndicated from BleepingComputer, 2026.

[9] Cloud Security Alliance. “AI Finds 21 FFmpeg Zero-Days for $1,000.” CSA AI Safety Initiative, 2026.

[10] Cloud Security Alliance. “SonicWall SMA Zero-Days: Edge Appliance Root Returns.” CSA AI Safety Initiative, July 2026.

[11] Cloud Security Alliance. “Agentic AI Threat Modeling Framework: MAESTRO.” CSA, February 2025.

[12] Cloud Security Alliance. “AI Controls Matrix v1.1.” CSA, 2026.

[13] Cloud Security Alliance. “Hugging Face’s Autonomous AI Agent Breach.” CSA AI Safety Initiative, 2026.

[14] Cloud Security Alliance. “Autonomous Agentic AI Adversaries.” CSA AI Safety Initiative, 2026.

← Back to Research Index