Summary
Key Points:
- Two zero-day vulnerabilities (CVE-2026-102489 and CVE-2026-102490) in the Zammad ticketing system were exploited in an AI-powered attack against the Dutch Institute for Vulnerability Disclosure (DIVD).
- The vulnerabilities allowed unauthenticated remote code execution and privilege escalation, leading to session hijacking and data exfiltration, although network segmentation limited further access.
- Users of Zammad versions 6.3.0 to 6.5.4 are advised to upgrade to version 7 or take the system offline to mitigate risks.
Technical Details: CVE-2026-102489 has a CVSS score of 9.4, enabling remote code execution and session leakage, while CVE-2026-102490 also scores 9.4, allowing local privilege escalation to root.
MITRE ATT&CK Techniques:
- T1203 - Exploit Public-Facing Application (Initial Access)
- T1068 - Exploit Public-Facing Application (Privilege Escalation)
IOCs Mentioned: None mentioned.
Join the discussion — sign up to comment, upvote, and save articles.