An autonomous AI agent breached the Dutch vulnerability disclosure institute by chaining two Zammad zero-days
DIVD says an AI agent operating without human direction chained two previously unknown Zammad flaws to go from session hijacking to root in seconds on September 21.
The Dutch Institute for Vulnerability Disclosure, a nonprofit of volunteer security researchers, has confirmed that its own network was breached by an autonomous AI agent. The agent chained two previously unknown vulnerabilities in the open-source Zammad ticketing platform to go from session hijacking to remote code execution to root privileges in seconds, BleepingComputer reports.
How the attack worked
DIVD says the first malicious access happened on September 21. The agent exploited CVE-2026-102489, an unauthenticated remote code execution flaw with session leakage affecting Zammad 6.3.0 through 6.5.4, then chained CVE-2026-102490, a local privilege escalation flaw affecting every version from 1.5.0 through the 7.1.0 alpha, to reach root. DIVD rates the chained scenario at CVSS 9.4, critical.
What made the incident stand out was the attacker's behavior. DIVD described it as "loud and very, very messy": the agent moved autonomously, deciding each next step itself, and left explanatory comments in its attack code justifying its actions, a non-human fingerprint the investigators used to reconstruct the incident. The irony is hard to miss: the organization exists to find and disclose other people's vulnerabilities, and it got breached through two of them before anyone knew they existed.
Network segmentation and fast incident response kept the attacker from moving deeper into DIVD's network, but the agent did read and exfiltrate data before being cut off. The full inventory of what was taken is still under investigation.
The disclosure timeline
DIVD applied its own disclosure principles to its own incident. Working with Merlon Security, it reproduced both flaws within days, reported them to Zammad on September 24, and began scanning the public internet for exposed instances. On September 30, it published the case file (DIVD-2026-00014), the CVE records, and a log-check script. The Dutch National Cyber Security Centre confirmed the flaws were being actively exploited as of September 21.
Zammad users were told to upgrade to version 7, where the RCE is not exploitable under current environmental conditions, or take instances offline immediately. The privilege escalation flaw had no patch as of October 1, and Zammad GmbH is still working on a fix. Attributing the agent to a human operator has not been established; no group has claimed responsibility.
Why this one matters
Security teams have long treated fully autonomous hacking agents as a lab curiosity. DIVD's incident is the clearest production case yet of an agent discovering the exploit chain shape on its own and executing it at machine speed, faster than any human-speed detection and response loop. The disclosure also lands in a week full of agentic-AI security news: AWS patched four vulnerabilities in its Loom agent orchestration platform in bulletins released October 2.
For defenders, the uncomfortable lesson is that the response has to be automated too. DIVD says the case files will keep expanding as the forensic work continues.