DIVD Says Zammad Zero-Days Enabled an AI-Driven Network Breach

Network router infrastructure protected by firewall and access controls

DIVD disclosed on September 30 that two Zammad zero-days were used in a September 21 breach. Its investigation remains ongoing, so the account should be treated as preliminary. DIVD said an AI agent chained the flaws within seconds, while network segmentation limited further movement inside the affected environment.

Two vulnerabilities with different roles

CVE-2026-102489 can allow session hijacking followed by remote code execution as the zammad service user. It affects versions 6.3.0 through 6.5.4. The issue is also present in 7.0.0 through 7.1.3, but the supplied record says it is not exploitable there under the stated environmental conditions. Its reported CVSS score is 9.4.

CVE-2026-102490 can allow a local zammad user to escalate privileges to root. It affects releases from 1.5.0 to before 7.1.0-alpha, and reporting described all released versions at disclosure as affected. Its reported CVSS score is also 9.4. Together, the issues illustrate why application-layer weaknesses can matter to the wider cyber-physical security landscape.

Response while guidance develops

Operators should follow current Zammad and DIVD guidance and apply a fixed release when one becomes available. While the investigation and remediation advice continue to evolve, isolating vulnerable systems can reduce exposure. The reported use of an AI agent is based on DIVD’s preliminary incident account; it should not be generalized into a broader claim about attacker capability or automation. Defenders should focus on the verified vulnerability boundaries, access paths, segmentation, and observable evidence in their own environments.

Sources and further reading

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *