AI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit - Help Net Security
An agentic AI-powered attack that hit the Dutch Institute for Vulnerability Disclosure (DIVD) on September 21 exploited two zero-day vulnerabilities in Zammad, an open-source helpdesk and customer support ticketing system.

An agentic AI-powered attack that hit the Dutch Institute for Vulnerability Disclosure (DIVD) on September 21 exploited two zero-day vulnerabilities in Zammad, an open-source helpdesk and customer support ticketing system.
From there they were able to access other services and read and exfiltrate data,” the Dutch non-profit shared on Wednesday.
A week ago, its computer security incident response team (CSIRT) revealed that it got hacked and that it started an investigation after reporting the incident to the Autoriteit Persoonsgegevens (the Dutch Data Protection Authority), the Dutch National Cyber Security Centre (NCSC-NL), and discussing their options with the police.
An update on Monday confirmed that the attack was “loud and very very messy.” “We could see the agent working automated, because after every action it decided the next step itself, at the speed of light and sloppy logic or pattern.
The Dutch NCSC advised making a copy of the application and network logs before installing the update: “If there is more information about the abuse of the second vulnerability, these logs can help you in the future to check if your system has been attacked.” Horizon3 researchers have published a technical rundown of CVE-2026-102489 and a proof-of-concept exploit.
It also looks like the agent skipped a few steps on its learning curve, because it has done some pretty dumb things, like polluting its own MITM attack with password spraying,” the organization said .
We’ve found signs of compromise that we’re still looking into, and until we can prove otherwise we assume breach.
CVE-2026-102490 , a privilege elevation vulnerability, allows authenticated attackers with low privileges (the local zammad user) to achieve root on the vulnerable system.
Recent findings by AI research laboratory Transluce have revealed that AI agents have also been using hacking tactics (vulnerability probing) while working on ordinary data retrieval tasks.
CVE-2026-102489 , which allows attackers to remotely execute malicious code without logging in, affects Zammad versions 6.3.0 to 6.5.4.
What happened
An agentic AI-powered attack that hit the Dutch Institute for Vulnerability Disclosure (DIVD) on September 21 exploited two zero-day vulnerabilities in Zammad, an open-source helpdesk and customer support ticketing system.
From there they were able to access other services and read and exfiltrate data,” the Dutch non-profit shared on Wednesday.
What changed
A week ago, its computer security incident response team (CSIRT) revealed that it got hacked and that it started an investigation after reporting the incident to the Autoriteit Persoonsgegevens (the Dutch Data Protection Authority), the Dutch National Cyber Security Centre (NCSC-NL), and discussing their options with the police.
An update on Monday confirmed that the attack was “loud and very very messy.” “We could see the agent working automated, because after every action it decided the next step itself, at the speed of light and sloppy logic or pattern.
Who is affected
The Dutch NCSC advised making a copy of the application and network logs before installing the update: “If there is more information about the abuse of the second vulnerability, these logs can help you in the future to check if your system has been attacked.” Horizon3 researchers have published a technical rundown of CVE-2026-102489 and a proof-of-concept exploit.
It also looks like the agent skipped a few steps on its learning curve, because it has done some pretty dumb things, like polluting its own MITM attack with password spraying,” the organization said .
Why it matters
We’ve found signs of compromise that we’re still looking into, and until we can prove otherwise we assume breach.
CVE-2026-102490 , a privilege elevation vulnerability, allows authenticated attackers with low privileges (the local zammad user) to achieve root on the vulnerable system.
Technical details
Recent findings by AI research laboratory Transluce have revealed that AI agents have also been using hacking tactics (vulnerability probing) while working on ordinary data retrieval tasks.
CVE-2026-102489 , which allows attackers to remotely execute malicious code without logging in, affects Zammad versions 6.3.0 to 6.5.4.
Both flaws are currently without a fix, but CVE-2026-102489 is not exploitable in Zammad versions 7.0.0 through 7.1.3 due to environment conditions.
Response
After determining, with the help of Merlon Security researchers, that the attackers had leveraged two Zammad zero-days, the DIVD CSIRT notified Zammad GmbH, which started working on fixes.
Zammad advised users to upgrade to Zammad v7.0 and later to prevent exploitation of CVE-2026-102489 and said that CVE-2026-102490 cannot be exploited remotely on its own.
What security teams should do
If you want to investigate whether you have been compromised based on our IoCs, you can download our log check script to check your Zammad logfiles for Indicators of Compromise,” the organization noted .
What remains unknown
Whether the DIVD breach was the result of agentic AI attempting to achieve a goal that was part of a larger cyber attack or a cyber capability test is unknown.
Attribution
Help Net Security: An agentic AI-powered attack that hit the Dutch Institute for Vulnerability Disclosure (DIVD) on September 21 exploited two zero-day vulnerabilities in Zammad, an open-source helpdesk and customer support ticketing system.
What to watch next
Watch for new exploitation reports and updated indicators of compromise.
Watch for updated vendor guidance and fixed-version details.