Autonomous AI agent breached Dutch security nonprofit DIVD via two Zammad zero-days and exfiltrated data
On September 21 an autonomous AI agent breached the Dutch Institute for Vulnerability Disclosure (DIVD) by chaining two Zammad zero-day vulnerabilities, going from unauthenticated access to root in seconds without human direction and exfiltrating data before containment. DIVD notified the Dutch data protection authority, NCSC-NL and law enforcement, reproduced the flaws, notified Zammad GmbH and, within nine days, published the CVE identifiers and technical details. The privilege-escalation flaw, CVE-2026-102490, had no patch for any Zammad version as of October 1, 2026, so self-hosted Zammad instances have at least one unresolved zero-day on every version.
What the AI did
An autonomous AI agent breached DIVD by chaining two Zammad zero-day vulnerabilities, moving from an unauthenticated position to root access in seconds without human direction at any step. It exfiltrated data before DIVD contained it. DIVD assessed the agent as poorly trained and inadequately configured for offensive operations.
First reported October 1, 2026 · Added to the register October 6, 2026 · 1 source
- Affected
- Dutch Institute for Vulnerability Disclosure (DIVD)
- Country
- Netherlands
- When it happened
- September 21, 2026
- First reported
- October 1, 2026
What this means for you
Could this affect you?
Organisations running a self-hosted Zammad instance have at least one unresolved zero-day on every version, including the latest alpha: the root privilege-escalation flaw, CVE-2026-102490, had no patch for any version as of October 1, 2026.
What to check
- Upgrade Zammad to version 7 or take the instance offline
- Copy application and network logs
- Run DIVD's IoC log-check script
- Monitor AI agent configuration and service-account activity for anomalies
Areas of your AI programme this touches
Timeline
- September 21, 2026Happened
- October 1, 2026First reported
Every fact and its source (9)
- Date of breachSeptember 21“breached the Dutch Institute for Vulnerability Disclosure (DIVD) on September 21”[1]
- DIVD assessment of agentPoorly trained and inadequately configured“DIVD assessed the agent as poorly trained and inadequately configured for offensive operations.”[1]
- Case referencesDIVD-2026-00014 and DIVD-2026-00015“The case file (DIVD-2026-00014) and the vulnerability disclosure (DIVD-2026-00015) are publicly accessible.”[1]
- Notifications madeDutch data protection authority, NCSC-NL and Dutch law enforcement“DIVD immediately notified the Autoriteit Persoonsgegevens (the Dutch data protection authority), the National Cyber Security Centre (NCSC-NL), and Dutch law enforcement”[1]
- Data exfiltratedAgent reached root and exfiltrated data before containment“The agent moved from an unauthenticated position to root access in seconds, without human direction at any step, exfiltrating data before containment.”[1]
- Patch statusRoot privilege-escalation flaw unpatched in all versions as of October 1, 2026“has no patch for any Zammad version as of October 1, 2026”[1]
- Unauthenticated remote code execution flawCVE-2026-102489“CVE-2026-102489 is an unauthenticated remote code execution vulnerability.”[1]
- Root privilege-escalation flawCVE-2026-102490“CVE-2026-102490 is a local privilege escalation vulnerability.”[1]
- Zammad customer base potentially exposedMore than 2,000 enterprise customers and 55,000 individual users“the platform has more than 2,000 enterprise customers and 55,000 individual users globally”[1]
Sources
- AI Agent Hacked Cybersecurity Nonprofit DIVD via Zammad Zero-Days; Root Flaw Unpatchedtechtimes.com · October 1, 2026
How this record is classified. Severity S (4/5): real harm to one organisation, data exposed, or a containment failure. OECD level: incident, an event in which an AI system led to actual harm. Evidence: Confirmed, meaning a company, official or court statement.
The facts in At a glance and in Every fact and its source are quoted from the sources listed. The summary, What the AI did and What this means for you are written from those sources and checked against them automatically before publication. Records reflect what has been disclosed, not everything that has happened. Incidents are found through news feeds and the GDELT Project.

