zero-day • Sysdig

Zammad Zero-Day Chain Hits KEV Deadline After AI Agent Breached DIVD

On 2 October 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two Zammad helpdesk flaws to its [KEV catalog](/wiki/cisa-kev.html "CISA Known Exploited Vulnerabilities") — Known Exploited Vulnerabilities — with a remediation deadline of 5 October.

Zammad Zero-Day Chain Hits KEV Deadline After AI Agent Breached DIVD

On 2 October 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two Zammad helpdesk flaws to its KEV catalog — Known Exploited Vulnerabilities — with a remediation deadline of 5 October. CVE-2026-102489 is a session-fixation issue that CISA says can lead to remote code execution as the `zammad` user. CVE-2026-102490 is improper privilege management that can let the local `zammad` user escalate to root. CISA notes the two can be chained. For U.S. federal civilian agencies the due date is today — and for anyone running internet-facing Zammad the signal is the same: patch or take the system offline now.

The chain was not found in a lab. On 21 September 2026 an agentic threat actor — an autonomous AI agent choosing each next step at machine speed — breached DIVD (the Dutch Institute for Vulnerability Disclosure), the volunteer nonprofit that scans the internet for exposed systems and warns owners. The agent exploited two then-unknown zero-days in Zammad, went from hijacked session to root in seconds, and exfiltrated data. DIVD detected the intrusion on 22 September, cut off its data centre, investigated with Merlon Security, and disclosed the case between 24 and 29 September. On 1 October DIVD confirmed data exfiltration; Sysdig’s Threat Research Team published a detailed technical write-up on 2 October.

Per DIVD and the CVE records, CVE-2026-102489 is practically exploitable on Zammad 6.3.0–6.5.4 (CVSS around 8.7). It is also present in 7.0.0–7.1.3 but, according to DIVD/Zammad, not exploitable under those runtime conditions. CVE-2026-102490 is described as local privilege escalation from 1.5.0 through 7.1.0-alpha (CVSS around 8.5); the chained impact has been assessed critical (CVSS 9.4). Zammad states that 7.0 and later are not exploitable for the remote stage, that hardening is included in 7.2.0, and that the LPE cannot be exploited remotely on its own — the attacker already needs local execution. The vendor received technical detail on CVE-2026-102490 late and continues work on advisories.

The attack was noisy: the agent left script comments explaining decisions ("no phishing", "no spam"), disrupted its own man-in-the-middle with password spraying, and moved messily — typical of non-deterministic agents rather than a stealthy human operator. It still succeeded. A helpdesk concentrates secrets: database credentials, mail and API tokens, links into Jira, Confluence and cloud services. DIVD confirmed stolen volunteer email addresses, signs of compromise in the CSIRT ticketing system, and concerns around the project support environment. Organisations that receive DIVD notices should watch for phishing impersonating DIVD volunteers.

Zammad reports more than 2,000 customers and about 55,000 users. Many Nordic municipalities, agencies and companies run open helpdesk stacks — sometimes with internet-exposed login. A three-day KEV deadline plus documented AI-driven exploitation makes this an immediate operations and investigation issue, not a "schedule a patch window next sprint" note.

What IT and security leads should do now

Upgrade to Zammad 7.2.0 (current stable) or at least 7.0+; take older 6.5 installs offline until upgraded. Isolate the helpdesk in its own network segment with default-deny egress. Preserve `/var/log/zammad` and web-server logs before rebuilds; run DIVD’s indicator script where available. Treat any sign of exploitation as full host compromise: rotate every secret stored on or reachable from the host. Monitor that the `zammad` process does not spawn shells, escalate to root, or open unfamiliar outbound connections — behaviour detection, not CVE signatures alone.

Sources & References

← All News Tools