Skip to main content

Zammad Zero-Days Exploited in AI-Powered DIVD Hack

0
Critical
Vulnerabilityremoterce
Published: 10/01/2026 (10/01/2026, 10:42:49 UTC)
Source: SecurityWeek

Description

Two zero-day vulnerabilities in the open-source Zammad ticketing system were exploited in an AI-powered attack against the Dutch Institute for Vulnerability Disclosure (DIVD). The flaws allowed attackers to hijack sessions, execute remote code, and escalate privileges to root. The attack led to data exfiltration within DIVD's environment, though network segmentation limited further compromise. Affected versions include Zammad 6.3.0 to 6.5.4, with later versions 7.0.0 to 7.1.3 containing the defect but not exploitable due to environment conditions. DIVD recommends upgrading to Zammad version 7 or taking the system offline. A verification script for detecting compromise is available.

Affected software

Affected versions
>=6.3.0 <=6.5.4>=7.0.0 <=7.1.3

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/01/2026, 14:44:06 UTC

Technical Analysis

The Dutch Institute for Vulnerability Disclosure was targeted in an automated AI-driven attack exploiting two zero-day vulnerabilities in Zammad. The first vulnerability (CVE-2026-102489, CVSS 9.4) enables unauthenticated remote code execution and session leakage. The second (CVE-2026-102490, CVSS 9.4) allows local privilege escalation to root. Combined, these flaws enabled attackers to hijack sessions, execute code remotely, and escalate privileges rapidly. The attackers pivoted from the compromised Zammad instance to other services and exfiltrated data, though network segmentation prevented deeper access. Affected versions are Zammad 6.3.0 through 6.5.4 and 7.0.0 through 7.1.3 (with exploitation in the latter limited by environment). DIVD has notified Zammad, which is developing a fix, and advises upgrading to version 7 or taking the system offline. DIVD also provides a verification script for detection and is scanning for vulnerable instances.

Potential Impact

The vulnerabilities allow unauthenticated attackers to remotely execute code and leak user sessions, and local users to escalate privileges to root. This enables full system compromise of affected Zammad instances, including session hijacking and root-level access. The attack against DIVD resulted in data exfiltration from the Zammad instance and potential compromise of other services. Network segmentation limited the attacker's lateral movement beyond the initial environment. Until remediation is applied, affected systems remain at high risk of compromise.

Mitigation Recommendations

Zammad is working on a fix for the reported zero-day vulnerabilities. Users are advised to upgrade to Zammad version 7 or later, or take the system offline until a patch is available. DIVD has published a verification script to detect indicators of compromise and is actively scanning for vulnerable instances. Organizations should apply the verification script to assess exposure and monitor for signs of compromise. Patch status is pending; check the official Zammad advisories for updates on fixes.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.7,"severitySource":"heuristic","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/zammad-zero-days-exploited-in-ai-powered-divd-hack/","fetched":true,"fetchedAt":"2026-10-01T14:43:10.877Z","wordCount":1033}

Threat ID: 6abe717fb45efb4220452613

Added to database: 10/01/2026, 14:43:11 UTC

Last enriched: 10/01/2026, 14:44:06 UTC

Last updated: 10/01/2026, 14:47:39 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses