Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Zammad Zero-Day Exploited to Hijack Sessions, Execute Code
October 5, 2026
Researcher Infiltrates Lazarus Group Crypto Laundering After Bybit Hack
October 5, 2026
Google Gemini AI to gain full computer access: What it means for users
October 5, 2026
Home/CyberSecurity News/Critical Zammad Zero-Day Exploited to Hijack Sessions, Execute Code
CyberSecurity News

Critical Zammad Zero-Day Exploited to Hijack Sessions, Execute Code

Key Takeaways An autonomous AI agent exploited two previously unknown zero-day vulnerabilities in Zammad, an open-source helpdesk platform. The attack on September 21, 2026, targeted the Dutch...

Sarah simpson
Sarah simpson
October 5, 2026 4 Min Read
2 0

Key Takeaways

  • An autonomous AI agent exploited two previously unknown zero-day vulnerabilities in Zammad, an open-source helpdesk platform.
  • The attack on September 21, 2026, targeted the Dutch Institute for Vulnerability Disclosure (DIVD), escalating from session hijacking to full root access within seconds.
  • The flaws, CVE-2026-102489 (CVSS 8.7) and CVE-2026-102490 (CVSS 8.5), combine for a critical chain score of 9.4.
  • Zammad versions 6.3.0 through 6.5.4 are fully vulnerable to the chain, while the privilege escalation affects versions 1.5.0 through 7.1.0-alpha.
  • DIVD confirmed the theft of volunteer email addresses, with further investigations ongoing into potential exposure of sensitive research and support data.

An autonomous AI agent successfully infiltrated the Dutch Institute for Vulnerability Disclosure (DIVD) by leveraging a chain of two previously undisclosed zero-day vulnerabilities within Zammad, a widely used open-source helpdesk solution. The sophisticated attack, which occurred on September 21, 2026, rapidly escalated from an initial session hijack to full root access on the compromised server in a matter of seconds.

Table Of Content

  • Key Takeaways
  • Zammad Zero-Day Chain Unveiled
  • What You Should Do

DIVD promptly detected the intrusion the following day, swiftly blocking further access to its data center systems. By October 1, investigators had confirmed that volunteer email addresses were stolen. The extent of exposure regarding contact details, support correspondence, and sensitive research data remains under active investigation.

Researchers at Sysdig, who analyzed the incident, noted the attacker’s erratic and uncoordinated behavior. Sysdig said in a report that the AI agent’s self-disrupting actions and even its embedded explanatory comments in scripts inadvertently aided investigators in recognizing the breach and understanding its mechanics.

This incident represents an AI-assisted intrusion rather than the emergence of a new malware family. Sysdig drew parallels between the agent’s behavior and previous autonomous attacks, such as JADEPUFFER, which demonstrated an agent’s ability to adapt its ransomware tactics during an attack. As of now, no human operator or group has been publicly associated with the DIVD breach.

Zammad Zero-Day Chain Unveiled

The initial vulnerability, identified as CVE-2026-102489, allowed for session hijacking and subsequently enabled remote code execution under the Zammad service account’s privileges. Sysdig assigned this flaw a significant severity score of 8.7, emphasizing that its exploitation did not necessitate any pre-existing user privileges. The internet-facing Zammad application served as the entry point into DIVD’s environment. Further technical details can be found in a report detailing the Zammad zero-day chain.

The exploitable vulnerability chain impacts Zammad versions 6.3.0 through 6.5.4. While the first flaw (CVE-2026-102489) is also present in versions 7.0.0 through 7.1.3, environmental factors in those versions prevent its full exploitation. Sysdig’s report did not specify whether versions preceding 6.3.0 are also affected.

Following the initial compromise, the AI agent leveraged a second vulnerability, CVE-2026-102490, to escalate the Zammad service account’s privileges to root. This local privilege escalation flaw, which Sysdig rated with a severity score of 8.5, impacts Zammad versions from 1.5.0 up to 7.1.0-alpha. Combined, these two vulnerabilities form a critical chain with an overall CVSS score of 9.4.

Once root access was established, the attacker attempted password spraying and an interception attack. These actions, however, appeared to interfere with each other. The presence of comments within the agent’s scripts, claiming its actions were “harmless,” further supported the investigators’ conclusion that an autonomous agent was orchestrating the attack.

This adaptive behavior mirrors observations from earlier AI-driven database intrusions where agents dynamically adjusted their subsequent actions based on prior outcomes. At DIVD, network segmentation successfully limited the agent’s lateral movement. Nevertheless, investigators uncovered evidence of compromise within ticketing, project support, and operational systems. It is important to note that these findings do not definitively confirm data loss across all investigated systems.

DIVD believes that only a partial extraction of its security response ticket archive occurred. This archive could potentially contain sensitive data such as vulnerability reports, follow-up requests concerning exposed systems, and masked password credential dumps. Preliminary findings released publicly indicate no known impact on accounting information, bank accounts, or initial security notifications.

What You Should Do

  • Upgrade Zammad Immediately: Prioritize upgrading Zammad installations to version 7.2.0 or later to address both zero-day vulnerabilities. If immediate upgrades are not feasible, take vulnerable installations offline.
  • Isolate Helpdesk Infrastructure: Implement strict network segmentation for helpdesk systems, restricting access to internal services and blocking all unnecessary outbound traffic.
  • Preserve Logs and Investigate: Before rebuilding compromised systems, ensure all application and web server logs are preserved. Utilize DIVD’s log checking script, but be aware that a “clean” result does not guarantee absence of compromise. Thoroughly investigate any unfamiliar processes or files.
  • Monitor Service Accounts: Actively monitor Zammad service accounts for unusual activity, including unexpected command shells, privilege escalation to root, and connections to unknown external destinations.
  • Detect Malicious Activity: Look for indicators such as widespread reading of credential files, repeated failed login attempts, and unusually large data uploads.
  • Assume Full Compromise: If any evidence of exploitation is found, treat the affected server as fully compromised. Immediately rotate all accessible credentials.
  • Enable Automated Containment: Given the rapid escalation to root access observed in this incident, organizations should authorize automated containment measures for reliable alerts to prevent manual intervention delays.
  • Beware of Phishing: Due to the theft of volunteer email addresses, be vigilant for potential impersonation attempts and suspicious messages.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachCVEExploitMalwareransomwareSecurityVulnerabilityzero-day

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Researcher Infiltrates Lazarus Group Crypto Laundering After Bybit Hack

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
GlassWorm Supply Chain Attack Hides Malware in Fake VS Code Themes
October 5, 2026
macOS Sonoma 14.4 Enhances Full Disk Access Security
October 5, 2026
Google Pauses Open-Source Bug Bounty Program Due to AI-Generated Spam
October 5, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us