News Date: 2026-09-30
An attack against the Dutch Institute for Vulnerability Disclosure has provided a striking example of what happens when software vulnerabilities are combined with machine-speed decision making. According to the organization, an autonomous AI agent chained two zero-day flaws in the Zammad helpdesk platform to compromise systems and rapidly explore the surrounding environment.
From Session Hijacking to Root
The vulnerabilities are identified as CVE-2026-102489 and CVE-2026-102490. Used together, they reportedly enabled session hijacking, remote code execution and privilege escalation from the Zammad service account to root. Once inside, the attacker accessed additional services and extracted data in a matter of seconds.
Zammad is an open-source ticketing and support platform available in hosted and self-managed forms. Helpdesk systems are attractive targets because support tickets frequently contain internal hostnames, screenshots, credentials, recovery instructions and detailed descriptions of operational problems. They can also be connected to email systems, identity providers and administrative tools.
DIVD previously described the attack as noisy and disorganized, but the automation behind it still made the intrusion dangerous. The agent reportedly selected its next actions without continuous human direction. Ironically, it also left explanations of its decisions behind, helping investigators reconstruct what happened.
Segmentation Limited the Damage
The incident did not progress deeper into DIVD's network because segmentation and incident-response measures restricted the attacker's available paths. That detail is important. Preventive security did not stop the initial compromise, but architectural controls reduced the blast radius after exploitation succeeded.
What Zammad Operators Should Do
- Upgrade affected deployments to Zammad version 7, which DIVD considers safe.
- Take vulnerable systems offline if they cannot be updated immediately.
- Invalidate existing sessions and rotate credentials accessible to the application.
- Review connections from the helpdesk server to internal services.
- Search for unexpected commands, new accounts, altered services and unusual data transfers.
I believe the larger lesson is not that AI has created an entirely new category of vulnerability. The weaknesses were still conventional software flaws. The difference was tempo. An autonomous attacker can test possibilities, change tactics and exploit connected services faster than a human analyst can process a conventional alert.
Defenders therefore need containment controls that work even when nobody has reviewed the incident yet. Strong segmentation, limited service permissions and automated isolation can turn an AI-speed compromise from an enterprise-wide emergency into a contained investigation.
