INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Dutch Institute for Vulnerability Disclosure Breached via Zammad ZeroDays

| 2026-10-04 11:45 CRITICAL LOW EXPLOITED VULNERABILITY
Executive Summary
AI-generated
On September 21st, Dutch vulnerability disclosure agency DIVD's systems were breached through two previously unknown vulnerabilities in Zammad, an open-source customer-support and ticketing platform. The attackers linked the zero-day vulnerabilities to gain root access to the system after remote code execution (RCE), exploiting CVE-2026-102489 and CVE-2026-102490. This incident affected DIVD's systems, but no specific number of users or data is mentioned in the sources. The attack works by chaining two Zammad vulnerabilities: one that can lead to session leakage and another that allows a local user to rise to root privileges. As of now, it appears that the attackers have successfully breached DIVD's infrastructure using AI-based attack automation, specifically Epic AI, although the specific details are unclear due to lack of public disclosure.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-102490, CVE-2026-102489 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

hxxp://••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-102490CVE-2026-102490 CVE-2026-102489CVE-2026-102489
Target & Sectors
BENELUX BENELUX
Incident Timeline
‎September 21st
Threat actors used newly discovered Zammad exploits to breach the Dutch Institute Vulnerability Disclosure (DIVD) system on September 21st.
‎September 21, 2026
Threat actors breached Dutch Institute Vulnerability Disclosure's systems on September 21, 2026.
organisation DIVD
‎September 24
Threat actors used newly discovered Zammad exploits to target the Dutch Institute vulnerability disclosure program on September 24.
‎2026/09/25
Threat actors used newly discovered Zammad exploits to breach the Dutch Institute vulnerability disclosure program on September 24, 2026.
‎September 30
The Dutch Institute disclosed a breach via newly discovered Zammad exploits, specifically two zero-day vulnerabilities exploited by attackers.
‎2026/10/04
Threat actors exploited two zero-day vulnerabilities in Zammad, tracked as CVE-2026-102489 and CVE-2026-102490, to gain root access to the system after remote code execution.
organisation CVSS
organisation DIVD
organisation CVE-2026
organisation CVSS-BT
organisation CVE-2026-102489
infrastructure 6.5
infrastructure 7.0
infrastructure 1.5.0
infrastructure 7.1.0-alpha
infrastructure 7.1.0
infrastructure 7.2.0
organisation Quest Technology Management
organisation SOC
infrastructure 6.3.0
infrastructure 6.5.4
infrastructure 7.0.0
infrastructure 7.1.3
organisation Merlon Security
organisation IP
organisation Slack
organisation GitLab
organisation Amnesty International
victims 2,000 customers
victims 55,000 users
organisation NFL
organisation CHANEL
Tactical Metrics
Metrics
infrastructure
‎1.5.0
Software Version
Metrics
infrastructure
‎7.1.0-alpha
Software Version
Metrics
infrastructure
‎6.3.0
Software Version
Metrics
infrastructure
‎6.5.4
Software Version
Metrics
infrastructure
‎7.0.0
Software Version
Metrics
infrastructure
‎7.1.3
Software Version
Metrics
infrastructure
‎7.1.0
Software Version
Metrics
infrastructure
‎6.5
Software Version
Metrics
infrastructure
‎7.0
Software Version
Metrics
infrastructure
‎7.2.0
Software Version
Metrics
victims
2,000
Customers
Metrics
victims
55,000
Users