DKDKCISSPSearch
Vulnerabilities

Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability

The Dutch Institute for Vulnerability Disclosure (DIVD) is staffed by volunteers and dedicated to ethically disclosing flaws it finds in systems to However, it became a target itself last week after noticing suspicious activity on September 24.

DKCISSP News DeskInfosecurity Magazine2 Oct 2026, 1:55 pm
Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability
Image courtesy of Infosecurity Magazine. Original report
DKCISSP REPORT

We urge everyone using any version of Zammad to update to version 7 or take it offline as soon as possible.” The vulnerabilities exploited in the attack are remote code execution bug CVE-2026-102489 and elevation of privileges flaw CVE-2026-102490, both of which have a CVSS score of 9.4 when chained.

On investigating, it became clear that AI was used in the attack, DIVD continued.

In a LinkedIn post on September 30, the organization revealed that its attackers exploited two zero-days in Zammad.

The Dutch Institute for Vulnerability Disclosure (DIVD) is staffed by volunteers and dedicated to ethically disclosing flaws it finds in systems to “make the digital world safer.” However, it became a target itself last week after noticing suspicious activity on September 24.

It makes patching, monitoring, access controls, air-gapped/immutable data storage, segmentation, and incident response even more important.” Burke said network segmentation was key to limiting the damage in cases like this, preventing access from spreading across the broader environment.

We can’t share more for now without getting in the way of the investigation.” Tim Burke, president and CEO of managed IT service provider Quest Technology Management, warned that AI-driven attacks are compressing detection and response timelines.

Delays matter more when attack activity happens at machine speed.”

Someone still needs to know what is happening in the environment and be able to act quickly,” he told Infosecurity .

What happened

We urge everyone using any version of Zammad to update to version 7 or take it offline as soon as possible.” The vulnerabilities exploited in the attack are remote code execution bug CVE-2026-102489 and elevation of privileges flaw CVE-2026-102490, both of which have a CVSS score of 9.4 when chained.

On investigating, it became clear that AI was used in the attack, DIVD continued.

What changed

In a LinkedIn post on September 30, the organization revealed that its attackers exploited two zero-days in Zammad.

The Dutch Institute for Vulnerability Disclosure (DIVD) is staffed by volunteers and dedicated to ethically disclosing flaws it finds in systems to “make the digital world safer.” However, it became a target itself last week after noticing suspicious activity on September 24.

Why it matters

It makes patching, monitoring, access controls, air-gapped/immutable data storage, segmentation, and incident response even more important.” Burke said network segmentation was key to limiting the damage in cases like this, preventing access from spreading across the broader environment.

Response

We can’t share more for now without getting in the way of the investigation.” Tim Burke, president and CEO of managed IT service provider Quest Technology Management, warned that AI-driven attacks are compressing detection and response timelines.

Attribution

Infosecurity Magazine: The Dutch Institute for Vulnerability Disclosure (DIVD) is staffed by volunteers and dedicated to ethically disclosing flaws it finds in systems to “make the digital world safer.” However, it became a target itself last week after noticing suspicious activity on September 24.

What to watch next

Watch for new exploitation reports and updated indicators of compromise.

Watch for updated vendor guidance and fixed-version details.

MORE IN VULNERABILITIES

More cybersecurity reporting

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCEThe Hacker News · 5 Oct 2026, 1:39 pmAttackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOTThe Hacker News · 5 Oct 2026, 1:00 pmCVE-2023-36025 (SmartScreen Bypass) Vulnerability: Analysis & Detection | HuntressHuntress · 4 Oct 2026, 5:30 amCritical FortiMail zero-day exploited in the wild (CVE-2026-104286) - Help Net SecurityHelp Net Security · 2 Oct 2026, 2:20 pm