# DIVD identifies Zammad zero-day chain behind network breach

_Published Wednesday, September 30, 2026 at 8:09 PM EDT · Security, AI · Latest · Tier 2 — Notable_

![DIVD identifies Zammad zero-day chain behind network breach — Primary](https://www.bleepstatic.com/content/hl-images/2026/09/30/zammad.jpg)

The Dutch Institute for Vulnerability Disclosure says two previously unknown Zammad vulnerabilities enabled the breach of its network. The flaws, CVE-2026-102489 and CVE-2026-102490, allowed session hijacking, remote code execution and escalation to root privileges.

DIVD says an autonomous AI agent exploited the chain and accessed and exfiltrated data within seconds. It reconstructed the incident using explanations the agent left behind. Network segmentation and incident response prevented deeper movement, but the investigation continues. DIVD notified Zammad and recommends that users upgrade to version 7, which it considers safe, or take vulnerable instances offline.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/divd-says-zammad-zero-days-enabled-ai-driven-network-breach/)

---
Canonical: https://techandbusiness.org/newswire/h3k8IeXxHMt-ZJ0Tap8Osf
Published: 2026-10-01T00:09:07.057Z
Story chronology: 2026-09-30T19:49:15.000Z
Retrieved: 2026-10-01T02:09:31.967Z
Publisher: Tech & Business (techandbusiness.org)
