DKDKCISSPSearch
VulnerabilitiesDEVELOPING

Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability

The Dutch Institute for Vulnerability Disclosure (DIVD) is staffed by volunteers and dedicated to ethically disclosing flaws it finds in systems to However, it became a target itself last week after noticing suspicious activity on September 24.

DKCISSP News DeskInfosecurity Magazine2 Oct 2026, 1:55 pm
Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability
Image courtesy of Infosecurity Magazine. Original report
DKCISSP REPORT

An agentic AI-powered attack that hit the Dutch Institute for Vulnerability Disclosure (DIVD) on September 21 exploited two zero-day vulnerabilities in Zammad, an open-source helpdesk and customer support ticketing system.

The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system.

We urge everyone using any version of Zammad to update to version 7 or take it offline as soon as possible.” The vulnerabilities exploited in the attack are remote code execution bug CVE-2026-102489 and elevation of privileges flaw CVE-2026-102490, both of which have a CVSS score of 9.4 when chained.

The Dutch Institute for Vulnerability Disclosure (DIVD) is staffed by volunteers and dedicated to ethically disclosing flaws it finds in systems to “make the digital world safer.” However, it became a target itself last week after noticing suspicious activity on September 24.

Previously, the nonprofit organization of volunteer security researchers said the attack was “loud and very, very messy,” driven by an AI agent that moved autonomously and decided its next steps without external intervention or direction.

In a LinkedIn post on September 30, the organization revealed that its attackers exploited two zero-days in Zammad.

From there they were able to access other services and read and exfiltrate data,” the Dutch non-profit shared on Wednesday.

The Dutch NCSC advised making a copy of the application and network logs before installing the update: “If there is more information about the abuse of the second vulnerability, these logs can help you in the future to check if your system has been attacked.”

According to the cybersecurity nonprofit, the two flaws, now identified as CVE-2026-102489 and CVE-2026-102490, enabled session hijacking, remote code execution, and escalation to root privileges.

CVE-2026-102490 , a privilege elevation vulnerability, allows authenticated attackers with low privileges (the local zammad user) to achieve root on the vulnerable system.

What happened

An agentic AI-powered attack that hit the Dutch Institute for Vulnerability Disclosure (DIVD) on September 21 exploited two zero-day vulnerabilities in Zammad, an open-source helpdesk and customer support ticketing system.

The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system.

What changed

We urge everyone using any version of Zammad to update to version 7 or take it offline as soon as possible.” The vulnerabilities exploited in the attack are remote code execution bug CVE-2026-102489 and elevation of privileges flaw CVE-2026-102490, both of which have a CVSS score of 9.4 when chained.

The Dutch Institute for Vulnerability Disclosure (DIVD) is staffed by volunteers and dedicated to ethically disclosing flaws it finds in systems to “make the digital world safer.” However, it became a target itself last week after noticing suspicious activity on September 24.

Who is affected

Previously, the nonprofit organization of volunteer security researchers said the attack was “loud and very, very messy,” driven by an AI agent that moved autonomously and decided its next steps without external intervention or direction.

In a LinkedIn post on September 30, the organization revealed that its attackers exploited two zero-days in Zammad.

Why it matters

From there they were able to access other services and read and exfiltrate data,” the Dutch non-profit shared on Wednesday.

The Dutch NCSC advised making a copy of the application and network logs before installing the update: “If there is more information about the abuse of the second vulnerability, these logs can help you in the future to check if your system has been attacked.”

Technical details

According to the cybersecurity nonprofit, the two flaws, now identified as CVE-2026-102489 and CVE-2026-102490, enabled session hijacking, remote code execution, and escalation to root privileges.

CVE-2026-102490 , a privilege elevation vulnerability, allows authenticated attackers with low privileges (the local zammad user) to achieve root on the vulnerable system.

Recent findings by AI research laboratory Transluce have revealed that AI agents have also been using hacking tactics (vulnerability probing) while working on ordinary data retrieval tasks.

Response

On investigating, it became clear that AI was used in the attack, DIVD continued.

After determining, with the help of Merlon Security researchers, that the attackers had leveraged two Zammad zero-days, the DIVD CSIRT notified Zammad GmbH, which started working on fixes.

What security teams should do

It makes patching, monitoring, access controls, air-gapped/immutable data storage, segmentation, and incident response even more important.” Burke said network segmentation was key to limiting the damage in cases like this, preventing access from spreading across the broader environment.

A week ago, its computer security incident response team (CSIRT) revealed that it got hacked and that it started an investigation after reporting the incident to the Autoriteit Persoonsgegevens (the Dutch Data Protection Authority), the Dutch National Cyber Security Centre (NCSC-NL), and discussing their options with the police.

What remains unknown

Whether the DIVD breach was the result of agentic AI attempting to achieve a goal that was part of a larger cyber attack or a cyber capability test is unknown.

Attribution

Infosecurity Magazine: The Dutch Institute for Vulnerability Disclosure (DIVD) is staffed by volunteers and dedicated to ethically disclosing flaws it finds in systems to “make the digital world safer.” However, it became a target itself last week after noticing suspicious activity on September 24.

Help Net Security: An agentic AI-powered attack that hit the Dutch Institute for Vulnerability Disclosure (DIVD) on September 21 exploited two zero-day vulnerabilities in Zammad, an open-source helpdesk and customer support ticketing system.

BleepingComputer: The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system.

What to watch next

Watch for new exploitation reports and updated indicators of compromise.

Watch for updated vendor guidance and fixed-version details.

MORE IN VULNERABILITIES

More cybersecurity reporting

Critical FortiMail zero-day exploited in the wild (CVE-2026-104286) - Help Net SecurityHelp Net Security · 2 Oct 2026, 2:20 pmCritical FortiMail zero-day exploited in the wild (CVE-2026-104286) - Help Net SecurityHelp Net Security · 2 Oct 2026, 2:20 pmTwo Zero-Days Exploited in Attack on Dutch Institute for VulnerabilityInfosecurity Magazine · 2 Oct 2026, 1:55 pmFortinet warns of critical FortiMail flaw exploited in zero-day attacksBleepingComputer · 2 Oct 2026, 4:12 am