← Back to news

Zammad Zero-Days Exploited in AI-Powered DIVD Hack

SecurityWeek01/10/2026, 10:42••
Read full article →

Summary

AI-Generated

Key Points:

  • Two zero-day vulnerabilities (CVE-2026-102489 and CVE-2026-102490) in the Zammad ticketing system were exploited in an AI-powered attack against the Dutch Institute for Vulnerability Disclosure (DIVD).
  • The vulnerabilities allowed unauthenticated remote code execution and privilege escalation, leading to session hijacking and data exfiltration, although network segmentation limited further access.
  • Users of Zammad versions 6.3.0 to 6.5.4 are advised to upgrade to version 7 or take the system offline to mitigate risks.

Technical Details: CVE-2026-102489 has a CVSS score of 9.4, enabling remote code execution and session leakage, while CVE-2026-102490 also scores 9.4, allowing local privilege escalation to root.

MITRE ATT&CK Techniques:

  • T1203 - Exploit Public-Facing Application (Initial Access)
  • T1068 - Exploit Public-Facing Application (Privilege Escalation)

IOCs Mentioned: None mentioned.

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.