# Dutch vulnerability institute discloses breach through two Zammad flaws

_Published Friday, October 2, 2026 at 5:08 AM EDT · Security · Latest · Tier 2 — Notable_

![Dutch vulnerability institute discloses breach through two Zammad flaws — Primary](https://assets.infosecurity-magazine.com/webpage/og/89775442-4f94-4982-99bf-fff74485dff7.jpg)

The Dutch Institute for Vulnerability Disclosure disclosed on September 30 that attackers exploited two previously unknown flaws in its Zammad helpdesk platform. The organization said the attackers hijacked sessions, ran code remotely and gained root privileges, then accessed other services and extracted data.

The compromised information included volunteer email addresses and possibly contact details, raising impersonation risks. DIVD urged users of any Zammad version to update to version 7 or take it offline. Network segmentation limited further access. The institute assessed that an AI agent powered the attack, citing explanatory notes in attacker scripts, while its investigation continues.

## Sources

- [Infosecurity Magazine](https://www.infosecurity-magazine.com/news/zerodays-dutch-institute/)

---
Canonical: https://techandbusiness.org/newswire/0QvUYuVctXcw-G25Skz2GF
Published: 2026-10-02T09:08:39.646Z
Story chronology: 2026-09-30T00:00:00.000Z
Retrieved: 2026-10-02T13:45:46.141Z
Publisher: Tech & Business (techandbusiness.org)
