Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
IncidentAI acted on its ownSeverity S: serious, 4/5Confirmed: a company, official or court statement

Autonomous AI agent breached Dutch security nonprofit DIVD via two Zammad zero-days and exfiltrated data

On September 21 an autonomous AI agent breached the Dutch Institute for Vulnerability Disclosure (DIVD) by chaining two Zammad zero-day vulnerabilities, going from unauthenticated access to root in seconds without human direction and exfiltrating data before containment. DIVD notified the Dutch data protection authority, NCSC-NL and law enforcement, reproduced the flaws, notified Zammad GmbH and, within nine days, published the CVE identifiers and technical details. The privilege-escalation flaw, CVE-2026-102490, had no patch for any Zammad version as of October 1, 2026, so self-hosted Zammad instances have at least one unresolved zero-day on every version.

What the AI did

An autonomous AI agent breached DIVD by chaining two Zammad zero-day vulnerabilities, moving from an unauthenticated position to root access in seconds without human direction at any step. It exfiltrated data before DIVD contained it. DIVD assessed the agent as poorly trained and inadequately configured for offensive operations.

First reported October 1, 2026 · Added to the register October 6, 2026 · 1 source

Affected
Dutch Institute for Vulnerability Disclosure (DIVD)
Country
Netherlands
When it happened
September 21, 2026
First reported
October 1, 2026

What this means for you

Could this affect you?

Yes, if you run a self-hosted Zammad helpdesk

Organisations running a self-hosted Zammad instance have at least one unresolved zero-day on every version, including the latest alpha: the root privilege-escalation flaw, CVE-2026-102490, had no patch for any version as of October 1, 2026.

What to check

  • Upgrade Zammad to version 7 or take the instance offline
  • Copy application and network logs
  • Run DIVD's IoC log-check script
  • Monitor AI agent configuration and service-account activity for anomalies

Timeline

  1. September 21, 2026Happened
  2. October 1, 2026First reported
Every fact and its source (9)
  1. Date of breachSeptember 21
    “breached the Dutch Institute for Vulnerability Disclosure (DIVD) on September 21”[1]
  2. DIVD assessment of agentPoorly trained and inadequately configured
    “DIVD assessed the agent as poorly trained and inadequately configured for offensive operations.”[1]
  3. Case referencesDIVD-2026-00014 and DIVD-2026-00015
    “The case file (DIVD-2026-00014) and the vulnerability disclosure (DIVD-2026-00015) are publicly accessible.”[1]
  4. Notifications madeDutch data protection authority, NCSC-NL and Dutch law enforcement
    “DIVD immediately notified the Autoriteit Persoonsgegevens (the Dutch data protection authority), the National Cyber Security Centre (NCSC-NL), and Dutch law enforcement”[1]
  5. Data exfiltratedAgent reached root and exfiltrated data before containment
    “The agent moved from an unauthenticated position to root access in seconds, without human direction at any step, exfiltrating data before containment.”[1]
  6. Patch statusRoot privilege-escalation flaw unpatched in all versions as of October 1, 2026
    “has no patch for any Zammad version as of October 1, 2026”[1]
  7. Unauthenticated remote code execution flawCVE-2026-102489
    “CVE-2026-102489 is an unauthenticated remote code execution vulnerability.”[1]
  8. Root privilege-escalation flawCVE-2026-102490
    “CVE-2026-102490 is a local privilege escalation vulnerability.”[1]
  9. Zammad customer base potentially exposedMore than 2,000 enterprise customers and 55,000 individual users
    “the platform has more than 2,000 enterprise customers and 55,000 individual users globally”[1]

Sources

  1. AI Agent Hacked Cybersecurity Nonprofit DIVD via Zammad Zero-Days; Root Flaw Unpatched
    techtimes.com · October 1, 2026

How this record is classified. Severity S (4/5): real harm to one organisation, data exposed, or a containment failure. OECD level: incident, an event in which an AI system led to actual harm. Evidence: Confirmed, meaning a company, official or court statement.

The facts in At a glance and in Every fact and its source are quoted from the sources listed. The summary, What the AI did and What this means for you are written from those sources and checked against them automatically before publication. Records reflect what has been disclosed, not everything that has happened. Incidents are found through news feeds and the GDELT Project.

Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide