مركز جمع المعلومات

معلومات التهديدات

An AI agent chained two Zammad zero-days to root a vulnerability-disclosure nonprofit.

DIVD says an AI agent went from a hijacked session to root on its Zammad server in seconds on September 21. No patches existed at the time of reporting.

هذا التقرير متاح بالإنجليزية فقط.

The Dutch Institute for Vulnerability Disclosure (DIVD) says an AI agent broke into its Zammad helpdesk server on September 21, 2026 by chaining two previously unknown flaws. DIVD detected the intrusion the next day and blocked access to systems in its data center. Help Net Security and The Register both reported the incident.


Why it matters. The attack went from a hijacked session to root in seconds. DIVD says the agent chose each next step on its own, and it made mistakes along the way, including polluting its own man-in-the-middle attempt with password spraying. Sloppy logic did not slow it down. Machine-speed exploitation shortens the window defenders have to react.


Technical detail. The chain uses two Zammad zero-days. CVE-2026-102489 is a remote code execution flaw affecting Zammad 6.3.0 through 6.5.4. Help Net Security reports it is not exploitable in 7.0.0 through 7.1.3. CVE-2026-102490 is a privilege escalation flaw affecting all Zammad versions, including the latest alpha. Together they let an attacker hijack a session, run code and escalate from the Zammad user to root.


Impact. DIVD has not said which data was accessed and states that it assumes breach. Network segmentation stopped the intruder from going deeper, though DIVD acknowledges some damage was done. DIVD worked with Merlon Security researchers and notified Zammad GmbH.


Mitigation. No patches existed for the zero-days at the time of reporting. DIVD advises upgrading to Zammad 7 or taking affected instances offline. Run the IOC check script DIVD published against your logs. Keep helpdesk servers segmented from the rest of the network, restrict internet exposure, and treat any ticketing system holding customer contact data as a high-value target.

يتطلب صلاحية دخول.

سجل الأحداث المشفّر الكامل وإجراءات المعالجة متاحة بعد تسجيل الدخول.