INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Dutch Institute for Vulnerability Disclosure Breached via Zammad ZeroDays
| 2026-10-04 11:45 CRITICAL LOW EXPLOITED VULNERABILITY
Executive Summary
AI-generated
On September 21st, Dutch vulnerability disclosure agency DIVD's systems were breached through two previously unknown vulnerabilities in Zammad, an open-source customer-support and ticketing platform. The attackers linked the zero-day vulnerabilities to gain root access to the system after remote code execution (RCE), exploiting CVE-2026-102489 and CVE-2026-102490. This incident affected DIVD's systems, but no specific number of users or data is mentioned in the sources. The attack works by chaining two Zammad vulnerabilities: one that can lead to session leakage and another that allows a local user to rise to root privileges. As of now, it appears that the attackers have successfully breached DIVD's infrastructure using AI-based attack automation, specifically Epic AI, although the specific details are unclear due to lack of public disclosure.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-102490, CVE-2026-102489 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
hxxp://••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-102490CVE-2026-102490
CVE-2026-102489CVE-2026-102489
Target & Sectors
BENELUX
BENELUX
Incident Timeline
September 21st
Threat actors used newly discovered Zammad exploits to breach the Dutch Institute Vulnerability Disclosure (DIVD) system on September 21st.
September 21, 2026
Threat actors breached Dutch Institute Vulnerability Disclosure's systems on September 21, 2026.
Click on any entity below to view its context and source!
organisation
DIVD
The attackers first breached DIVD’s systems on September 21, 2026.
September 24
Threat actors used newly discovered Zammad exploits to target the Dutch Institute vulnerability disclosure program on September 24.
2026/09/25
Threat actors used newly discovered Zammad exploits to breach the Dutch Institute vulnerability disclosure program on September 24, 2026.
September 30
The Dutch Institute disclosed a breach via newly discovered Zammad exploits, specifically two zero-day vulnerabilities exploited by attackers.
2026/10/04
Threat actors exploited two zero-day vulnerabilities in Zammad, tracked as CVE-2026-102489 and CVE-2026-102490, to gain root access to the system after remote code execution.
Click on any entity below to view its context and source!
organisation
CVSS
The vulnerabilities exploited in the attack are remote code execution bug CVE-2026-102489 and elevation of privileges flaw CVE-2026-102490, both of which have a CVSS score of 9.4 when chained.
The first vulnerability, tracked as
CVE-2026-102489
, carries a CVSS score of 8.7.
organisation
DIVD
The Dutch vulnerability disclosure agency DIVD discovered the vulnerabilities, CVE-2026-102489 and CVE-2026-102490, while investigating the incident.
A separate casefile on the incident explained that volunteer data including DIVD email addresses and possibly contact details was compromised, increasing the risk that malicious actors may try to impersonate DIVD staff.
After exploiting the vulnerabilities, the attacker was able to access other services, read and exfiltrate data from DIVD's systems, all actions performed in a matter of seconds, thanks to AI automation.
organisation
CVE-2026
When chained with the second vulnerability, CVE-2026-102489 carries a CVSS-BT score of 9.4, rated critical.
organisation
CVSS-BT
When chained with the second vulnerability, CVE-2026-102489 carries a CVSS-BT score of 9.4, rated critical.
organisation
CVE-2026-102489
The vendor said CVE-2026-102489 is exploitable only on unsupported Zammad 6.5 and older releases, while Zammad 7.0 and later are not affected in practice.
infrastructure
6.5
The vendor said CVE-2026-102489 is exploitable only on unsupported Zammad 6.5 and older releases, while Zammad 7.0 and later are not affected in practice.
infrastructure
7.0
The vendor said CVE-2026-102489 is exploitable only on unsupported Zammad 6.5 and older releases, while Zammad 7.0 and later are not affected in practice.
infrastructure
1.5.0
infrastructure
7.1.0-alpha
The vulnerability affects Zammad versions 1.5.0 to 7.1.0-alpha.
infrastructure
7.1.0
DIVD said versions from 1.5.0 through the 7.1.0 alpha release were affected.
infrastructure
7.2.0
organisation
Quest Technology Management
We can’t share more for now without getting in the way of the investigation.”
Tim Burke, CEO of managed IT service provider Quest Technology Management, warned that AI-driven attacks are compressing detection and response timelines.
organisation
SOC
“For companies without a dedicated SOC, continuous monitoring and visibility matter more.
infrastructure
6.3.0
DIVD said it affects Zammad versions 6.3.0 through 6.5.4.
infrastructure
6.5.4
DIVD said it affects Zammad versions 6.3.0 through 6.5.4.
infrastructure
7.0.0
The underlying vulnerable code is also present in versions 7.0.0 through 7.1.3, but DIVD said environmental conditions prevent exploitation on those releases.
infrastructure
7.1.3
The underlying vulnerable code is also present in versions 7.0.0 through 7.1.3, but DIVD said environmental conditions prevent exploitation on those releases.
organisation
Merlon Security
DIVD detected suspicious activity the following day, blocked access to its data-centre infrastructure and began a forensic investigation with incident-response company Merlon Security.
DIVD discovered the zero-day vulnerabilities in collaboration with Merlon Security.
organisation
IP
DIVD warned that the extracted material may include IP addresses of vulnerable systems, vulnerability reports and portions of credential dumps with masked passwords.
organisation
Slack
Reviews of its Google Workspace, Slack, GitHub, GitLab, Jira and Confluence environments remain ongoing.
organisation
GitLab
Reviews of its Google Workspace, Slack, GitHub, GitLab, Jira and Confluence environments remain ongoing.
organisation
Amnesty International
The solution is available as a self-hosted or hosted service, and Zammad
claims on its website
that it has over 2,000 customers and 55,000 users, including De’Longhi, Amnesty International, and NextCloud.
victims
2,000 customers
The solution is available as a self-hosted or hosted service, and Zammad
claims on its website
that it has over 2,000 customers and 55,000 users, including De’Longhi, Amnesty International, and NextCloud.
victims
55,000 users
The solution is available as a self-hosted or hosted service, and Zammad
claims on its website
that it has over 2,000 customers and 55,000 users, including De’Longhi, Amnesty International, and NextCloud.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Tactical Metrics
Metrics
Metrics
infrastructure
7.1.0-alpha
Software Version
The vulnerability affects Zammad versions 1.5.0 to 7.1.0-alpha.
Metrics
infrastructure
6.3.0
Software Version
DIVD said it affects Zammad versions 6.3.0 through 6.5.4.
Metrics
infrastructure
6.5.4
Software Version
DIVD said it affects Zammad versions 6.3.0 through 6.5.4.
Metrics
infrastructure
7.0.0
Software Version
The underlying vulnerable code is also present in versions 7.0.0 through 7.1.3, but DIVD said environmental conditions prevent exploitation on those releases.
Metrics
infrastructure
7.1.3
Software Version
The underlying vulnerable code is also present in versions 7.0.0 through 7.1.3, but DIVD said environmental conditions prevent exploitation on those releases.
Metrics
infrastructure
7.1.0
Software Version
DIVD said versions from 1.5.0 through the 7.1.0 alpha release were affected.
Metrics
infrastructure
6.5
Software Version
The vendor said CVE-2026-102489 is exploitable only on unsupported Zammad 6.5 and older releases, while Zammad 7.0 and later are not affected in practice.
Metrics
infrastructure
7.0
Software Version
The vendor said CVE-2026-102489 is exploitable only on unsupported Zammad 6.5 and older releases, while Zammad 7.0 and later are not affected in practice.
Metrics
Metrics
victims
2,000
Customers
The solution is available as a self-hosted or hosted service, and Zammad
claims on its website
that it has over 2,000 customers and 55,000 users, including De’Longhi, Amnesty International, and NextCloud.
Metrics
victims
55,000
Users
The solution is available as a self-hosted or hosted service, and Zammad
claims on its website
that it has over 2,000 customers and 55,000 users, including De’Longhi, Amnesty International, and NextCloud.
Intelligence Sources
Dailysecu
2026-10-04
Infosecurity-Magazine
2026-10-02
Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability Disclosure
Infosecurity-Magazine
BleepingComputer
2026-09-30
DIVD says Zammad zero-days enabled AI-driven network breach
BleepingComputer
HackRead
2026-10-03
Mastodon BleepingComputer
2026-09-30
The Dutch Institute for Vulnerability Disclosure (DIVD) says...
Mastodon BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T12:23
Comprehensive Tactical Telemetry
Highly Correlated Entities
17x
organisation
Identified Entity
DIVD
entity
10x
infrastructure
Software Version
1.5.0
version
6x
timeline
Temporal Reference
Zammad 6.3.06.5.4
date
4x
tactic
Cyber Operation Type
Privilege Escalation
tactic
3x
vulnerability
CVSS Score
9
score
2x
tactic
MITRE ATT&CK Technique
T1588.001 - Malware
technique
2x
vulnerability
Exploited CVE
CVE-2026-102489
cve
Contextual Telemetry
Context Block
10 METRICS
general metric
Zeroday
2
zeroday
target region
Target Country
Netherlands
country
general metric
Vulnerabilities
102,490
vulnerabilities
general metric
Version
7
version
industry
Targeted Sector
Technology
sector
source region
Origin Country
Netherlands
country
general metric
Zammad
6
zammad
general metric
Days
0
days
victims
Customers
2,000
customers
victims
Users
55,000
users
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.