Sev0

AI security incidents, tracked

All incidents / AI-run attack

Autonomous AI agent chained Zammad zero-days to breach Dutch nonprofit DIVD

Dutch Institute for Vulnerability Disclosure (DIVD), disclosed 24 Sep 2026 AI-run attack Data exposed Medium

What happened

The Dutch Institute for Vulnerability Disclosure said an autonomous AI agent exploited two zero-day flaws in the open-source Zammad ticketing system to hijack a session, run code and gain root on its network within seconds, reading and exfiltrating some data before network segmentation contained it. The agent left detailed logs of its own decisions.

DIVD, a nonprofit of volunteer security researchers, says the attacker first reached its systems on 21 September 2026; it cut off its datacenter the next day and disclosed the breach on 24 September. On 30 September it said an automated AI agent exploited two previously unknown Zammad flaws, CVE-2026-102489 and CVE-2026-102490, to carry out session hijacking, remote code execution and privilege escalation to root in a matter of seconds. The agent read and took some data from DIVD systems, though the organization did not detail what. DIVD described the agent as loud and messy, deciding each next step on its own and even interfering with its own password-spraying through an adversary-in-the-middle action, which left a clear forensic trail. Zammad is used by more than 2,000 organizations. DIVD urged users to upgrade to version 7 or take instances offline.

How it happened

AI-run attack: Autonomous intrusion. The attacker's own AI agent carried out the break-in, working through the steps with little human involvement.

Sources do not say whose AI model was involved. The product was Zammad, which is open source, a type of AI agent. Vulnerability IDs: CVE-2026-102489, CVE-2026-102490.

Impact

Data was exposed. Data involved: internal documents. The impact was confined to one organization and its users or customers.

Severity is rated Medium, calculated from how far the incident reached and how sensitive the data was.

Was the AI at fault?

No. The failure was in the systems, settings or people around the AI, not in the model's behaviour.

Status and timeline

Confirmed by the affected organization, the AI vendor, a regulator or a named security research firm.

It happened or began on 21 Sep 2026. It became public on 24 Sep 2026, 3 days later.

DIVD notified Dutch police, the data protection authority and the national cyber security centre and promised further updates on 2026-10-01. It published the two CVEs and remediation guidance.

Sources

  1. https://www.bleepingcomputer.com/news/security/divd-says-zammad-zero-days-enabled-ai-driven-network-breach/
  2. https://www.helpnetsecurity.com/?p=386522
  3. https://scworld.com/brief/ai-agent-exploits-zero-day-flaws-in-zammad-ticketing-system
  4. https://securityaffairs.com/200126/hacking/ai-agent-chains-zammad-zero-days-to-take-over-divd-systems-in-seconds.html

Related incidents

Cite as: Sev0, "Autonomous AI agent chained Zammad zero-days to breach Dutch nonprofit DIVD", https://sev0.fyi/incidents/2026-09-24-divd-zammad-zero-day-ai-agent-breach/. Data for this record: incidents.json.