The Dutch Institute for Vulnerability Disclosure has named the flaws behind the breach of its own network: CVE-2026-102489, a remote code execution flaw in the open-source Zammad ticketing platform from version 6.3 onward, and CVE-2026-102490, a local privilege escalation affecting 1.5.0 to 7.1.0-alpha. Used together they enabled session hijacking, remote code execution and escalation from Zammad user to root, "in seconds, due to the agentic part of this hack", after which the attacker reached other services and exfiltrated data. DIVD had previously described the intrusion as driven by an AI agent that chose its own next steps; it reconstructed the chain partly because the agent left readable explanations of its decisions. Network segmentation and incident response contained the intrusion before deeper movement. DIVD found the flaws with Merlon Security, notified Zammad, and is alerting other operators; it recommends upgrading to version 7 or taking instances offline, noting Zammad claims more than 2,000 customers.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-10-01 |
| Source | BleepingComputer |
| Reliability | Tier 2 |
| CVEs | CVE-2026-102489, CVE-2026-102490 |