CVE-2026-102489 & CVE-2026-102490: An AI Agent Chained These Zammad Zero-Days to Breach DIVD
DIVD, the nonprofit that discloses vulnerabilities for a living, was breached through its own Zammad helpdesk in what it calls an agentic AI-powered attack chaining CVE-2026-102489 and CVE-2026-102490. The RCE half is patchable. The root-level flaw still has no fix.

DIVD, the Dutch Institute for Vulnerability Disclosure, the organization that finds and reports flaws in other people's software, was breached through its own Zammad helpdesk on September 21, 2026. While investigating that breach, DIVD's own researchers found two zero-days in Zammad: CVE-2026-102489, a session fixation flaw that lets a remote attacker run code as the Zammad service user, and CVE-2026-102490, a local privilege escalation flaw that lets that same user become root on every version of Zammad ever released, including the newest alpha build. DIVD says the attack was agentic, an AI system chaining both flaws end to end in seconds. CISA added both CVEs to its Known Exploited Vulnerabilities catalog on October 2, and only one half of the chain has a real fix.
How the Two Flaws Chain Together
CVE-2026-102489 is a session fixation issue, tracked under CWE-384, in how Zammad manages user sessions. DIVD describes it as remote code execution as the Zammad user stemming from session leakage, letting a remote attacker take over a session and run commands with the privileges of the Zammad service account without needing valid credentials first. CVE-2026-102490 is tracked under CWE-269, improper privilege management: once an attacker holds that Zammad-user foothold, a flaw in how Zammad manages its own privileges lets it escalate straight to root. Neither flaw is catastrophic entirely on its own. Chained together, they turn a remote, credential-free request into full control of the server Zammad runs on, which is exactly what DIVD's own incident showed happening in practice.
Who's Affected
Zammad 6.3.0 through 6.5.4 are vulnerable to CVE-2026-102489; the flaw is also present in 7.0.0 through 7.1.3 but DIVD says it is not exploitable there due to environmental conditions. CVE-2026-102490 is worse in scope: it affects every Zammad release from 1.5.0 up to and including the 7.1.0 alpha build, the entire supported history plus the newest pre-release code. Zammad 7.2, released September 23, 2026, predates DIVD's September 24 notification, and DIVD's own scoring notes suggest it closes CVE-2026-102489 but it does not touch CVE-2026-102490. CVSS tells a layered story here. DIVD's own scoring gives CVE-2026-102489 an 8.7 on its own and 9.4 when scored as part of the chain with CVE-2026-102490, while VulnTracker shows 9.8 critical for both CVE pages individually. Whichever number you track, both are rated critical, network-exploitable, with no privileges or user interaction required for the full chain.
An AI Agent Did the Chaining
DIVD is not a typical victim. It is the nonprofit that runs coordinated vulnerability disclosure cases for other organizations, and it got breached through the same kind of software it tells other people to patch. What makes this one stand out is how DIVD describes the attack itself: an agentic, AI-powered intrusion that hijacked a session through CVE-2026-102489, ran code as the Zammad user, and escalated to root through CVE-2026-102490, all in seconds, with the speed and chaining DIVD attributes directly to AI automation rather than a human operator working through the steps by hand. DIVD found both flaws by investigating its own compromise, reported them to Zammad on September 24, and began scanning the internet for other exposed Zammad instances two days later.
Reading It on VulnTracker
The CVE-2026-102489 and CVE-2026-102490 pages on VulnTracker both show 9.8 critical scores and Actively Exploited banners, though their EPSS scores diverge: 0.6 percent for the RCE half, higher than 46 percent of all CVEs, against 0.3 percent for the privilege escalation half. SSVC marks CVE-2026-102489 as automatable and CVE-2026-102490 as not, a useful distinction since the RCE half can scale on its own while the root-level flaw needs that foothold first. CWE-384 and CWE-269 are tagged on their respective pages, and both carry the same October 5 remediation deadline. Track both CVEs to see which one gets a real fix first.
What to Do Now
Upgrading to Zammad 7.2 or later appears to close CVE-2026-102489 based on DIVD's own scoring notes, so get there first if you have not already. CVE-2026-102490 has no fix in any version, including that same 7.2 release, so patching alone will not close the chain. Restrict who can reach your Zammad instance, harden the zammad local user's permissions on the host, and run DIVD's published indicator-of-compromise script against your logs. Because DIVD found this by investigating an attack that happened before any public disclosure, assume patching alone will not remove an attacker who already got in: rotate credentials and secrets tied to the Zammad service, review scheduled tasks and cron jobs, check for new admin accounts, and treat anything suspicious as a full incident rather than a vulnerability to close quietly. Federal agencies face an October 5, 2026 remediation deadline under BOD 26-04 for both CVEs, a reasonable floor for anyone running Zammad.
CVE-2026-102489 and CVE-2026-102490 are a reminder that even the organizations built to catch zero-days are running the same exposed software everyone else is. If Zammad is part of your stack, don't wait for a patch before you start checking for compromise. Track CVE-2026-102489 and CVE-2026-102490 on VulnTracker to know the moment a real fix ships for both.
References
DIVD Case DIVD-2026-00015 · DIVD record for CVE-2026-102489 · DIVD record for CVE-2026-102490 · AI-powered attack reporting (SecurityWeek)