An autonomous AI agent chained two Zammad zero-days to breach DIVD and hit root in seconds, exposing why human-paced review cannot keep pace.
An autonomous, attacker-operated AI agent breached the Dutch Institute for Vulnerability Disclosure on September 21, 2026, chaining two previously unknown zero-days in the Zammad helpdesk platform to reach root access in seconds. The target matters as much as the speed: DIVD is a volunteer-staffed nonprofit whose entire mission is finding vulnerabilities, reporting them to vendors, and warning affected system owners, not a bank or a defense contractor, and nobody had modeled a vulnerability-disclosure organization as a high-value target before an AI agent found it first.
Sources: Help Net Security, Security Affairs
What happened at DIVD
DIVD runs Zammad internally as its own ticketing and helpdesk system. On September 21, 2026, an AI agent operating on the attacker side exploited two flaws in that software and, in DIVD's own words, used them together to "hijack sessions, run code remotely and escalate privileges from the Zammad user to root, in seconds, due to the agentic part of this hack." Public coverage followed starting October 1, 2026, once DIVD and the outside researchers who assisted it had pieced together what happened.
Sources: Security Affairs, Help Net Security
DIVD's IT and incident response teams caught the activity and brought in Merlon Security to help with the investigation. Network segmentation kept the intrusion from spreading further through DIVD's wider environment, but the agent had already reached root on the Zammad host well before any human had a realistic chance to intervene. The gap between first access and root was not a detection failure in the usual sense, the window to detect and react simply did not exist at human speed.
Sources: Security Affairs
Why DIVD is the wrong target to get breached
DIVD exists to find vulnerabilities, coordinate disclosure with vendors, and warn system owners before attackers get there first. It is staffed largely by volunteers and runs on the premise that the security community can out-cooperate attackers if it moves fast and shares what it finds. A breach of DIVD's own ticketing system is not just another helpdesk compromise, it is a breach of the exact kind of organization that the rest of the security ecosystem relies on to be trustworthy and uncompromised. Threat modeling for most nonprofits in this space has historically focused on the vulnerabilities they handle, not on the possibility that the organization itself becomes the entry point.
Sources: Security Affairs
That gap in threat modeling is itself the news. Nobody writing a risk assessment for a vulnerability-disclosure nonprofit in early 2026 was likely budgeting for an autonomous attacker-side agent finding two unpatched zero-days in the group's own helpdesk software and chaining them to root before a human noticed. The DIVD breach is a data point for a broader shift already visible across other incidents this year, where AI agents on the attacker side are showing up against targets that were never ranked as high-value, simply because the agents are cheap enough to run against anything reachable rather than only against targets worth a human operator's time.
The two zero-days the agent chained
The breach relied on a classic pairing: an unauthenticated way in, followed by a local escalation to root. CVE-2026-102489 is a remote code execution flaw in Zammad that required no authentication at all, affecting versions 6.3.0 through 6.5.4. CVE-2026-102490 is a privilege escalation flaw that let a local Zammad user reach root, and it reached further than the first bug: it affects every version of Zammad, including the newest 7.1.3 release and the current alpha build.
Sources: Help Net Security, Security Affairs
- CVE-2026-102489 (unauthenticated RCE, Zammad 6.3.0-6.5.4): a foothold with no credentials and no prior access needed.
- CVE-2026-102490 (privilege escalation to root, affecting every Zammad version including the latest alpha): turns that low-level foothold into full control of the host.
- Chained together, the two bugs took the agent from zero access to root, which is what let it hijack active sessions and run arbitrary code before pivoting toward other services.
That version spread cuts the other way from what a quick skim suggests. The privilege escalation bug is not confined to the newer 7.x line, it affects every Zammad version including the current alpha, so organizations that had already upgraded past the vulnerable RCE range gained no protection from the second half of the chain. DIVD says both flaws are currently without a fix. Upgrading to version 7 closes the unauthenticated entry point only because of an unrelated environment condition that happens to block it there, not because the underlying bug was patched, and the privilege escalation path still runs through every release.
Sources: Help Net Security
Zammad is used by more than 2,000 customers and roughly 55,000 users, and DIVD says neither flaw has a fix yet. Its own guidance is blunt: upgrade to version 7 or take the instance offline, then run DIVD's published log-check script against the Zammad logs to check for indicators of compromise. There is no patched release to wait for.
The agent was sloppy, and that sloppiness is what saved the forensics
DIVD did not describe a flawless machine. Investigators called the intrusion loud and "very very messy," the product of an agent working automated with what DIVD characterized as sloppy logic rather than careful tradecraft. The clearest example: after establishing a man-in-the-middle position inside the network, the same agent then ran password spraying straight through that position, polluting the foothold it had just won. DIVD listed this among the several "pretty dumb things" the agent did during the intrusion, the kind of self-defeating move an experienced human operator would avoid on instinct.
Sources: Help Net Security
The sharpest detail in DIVD's account is that the agent's own habits worked against it. The same verbosity that likely made the agent effective at grinding through an exploit chain without human hand-holding also made it talkative in a way no skilled human attacker would be: the agent left extensive self-commentary on what it was doing and why at each step. DIVD says that overexplaining is exactly what made reverse-engineering the attack easier after the fact, turning what should have been a hard forensic reconstruction into something closer to reading a narrated log.
Sources: Help Net Security
The irony is specific and worth sitting with: an agent built to attack efficiently narrated its own reasoning so thoroughly that it handed defenders a readable transcript of the attack. A quiet, surgical human operator would not have made that mistake, and a future version of this same agent, with the chattiness trained out, would not either.
Why speed, not cleverness, is the real story
Neither CVE in this chain required anything exotic to exploit once found. What made the DIVD breach notable is that a single automated chain went from unauthenticated access to root in seconds, a pattern also seen in the PaperCut campaign where AI agents breached 11 organizations in 26 seconds once the automation was set loose on exposed targets. A human operator running the same two exploits by hand, one command at a time, confirming each step before moving to the next, could not match that timeline even with both exploits already written and ready to use.
Sources: Help Net Security
That is the part that should unsettle anyone thinking about AI governance on either side of a system. The attacker here was not smarter than a skilled human red-teamer, the published exploits were not conceptually novel. It was just faster, and it did not pause between steps the way a person naturally does to check whether something looked off. A detection process built around a human noticing an anomaly in a dashboard, opening a ticket, and escalating it up a chain of approvals is built for a world where the attacker also moves at roughly human speed. Mean time to detect an intrusion is still commonly measured in hours or days across the industry. DIVD's own account makes clear that assumption broke down completely inside a single incident that resolved to root before anyone could react.
| Factor | Human-paced attack response | Machine-speed autonomous-agent attack |
|---|---|---|
| Time from access to root | Hours to days, limited by how fast a person can chain exploits manually | Seconds, per DIVD's account of the Zammad chain |
| Who notices first | An analyst reviewing alerts, logs, or an anomaly report | Nobody, in real time; the activity is reconstructed afterward from traces |
| Scale per attempt | One target at a time, bounded by the operator's own pace | Every reachable instance, in parallel, with no manual pivoting required |
| How mistakes play out | An attacker notices and corrects a bad move before repeating it | The same sloppy move, like password spraying through its own MITM position, repeats at machine speed until stopped |
| What actually stops it | A human intervening before the damage compounds | Nothing at runtime; only removing the flaw before deployment stops the chain from existing at all |
The governance argument this incident actually supports
The DIVD breach is an attack story, not a software-development story, and it would be dishonest to stretch it into one. But the underlying logic generalizes in a way worth stating precisely. On the attacker's side, a human-paced process cannot keep up with an agent that chains two zero-days and reaches root in seconds. On the defender's side, building with AI coding agents, the equivalent mismatch shows up earlier in the lifecycle: a team that relies on a reviewer eventually noticing a dangerous pattern in AI-generated code is making the same bet DIVD's attacker exploited, that a human will be fast enough, attentive enough, and present at the right moment to catch the problem before it matters. The convergence gate exists for exactly that gap: a deterministic check that blocks a merge until flagged issues hit zero, so the control does not depend on a person catching something at the wrong hour before it ships.
The boundary here needs to be explicit, because the comparison only holds up to a point. TLM Forge audits specs before code is generated, reviews the resulting diff independently, runs an adversarial red-team pass against the code, and gates the merge until issues are resolved. That is pre-deployment governance for teams building with AI coding agents, applied before anything reaches a running system. It is not intrusion detection, it does not watch production traffic, and it would not have been the tool that caught an attacker already inside a live Zammad instance. What it targets is the vulnerability before it ships, on the premise that the cheapest and most reliable time to stop a chain like CVE-2026-102489 plus CVE-2026-102490 is before either flaw exists in a deployed codebase, not after an agent has already found both in production.
Put the two cases side by side and the lesson is less about any single product and more about where the bottleneck has to sit. DIVD's breach shows a human-paced defense losing to a machine-speed attacker during live operation. The equivalent risk during software delivery is a human-paced code review losing to a machine-speed coding agent that can generate, and merge, a vulnerable pattern faster than a reviewer can read the diff carefully. Both cases point to the same fix: push the check earlier, make it automatic, and do not let it pass until the specific issues it flags are gone, rather than trusting that a person will be watching closely enough at the moment it counts.
None of this requires treating an AI coding agent as an adversary the way DIVD had to treat the agent that broke into its helpdesk. The point is narrower and more practical: speed changes which controls actually work. A control that depends on a tired reviewer catching a subtle authorization bug in a large diff, at whatever hour the agent happened to generate it, is a control built on the same assumption DIVD's incident broke, that there will be enough time and enough attention before the mistake matters. Spec audits, independent diff review, an adversarial pass, and a gate that will not budge until flagged issues are resolved do not need a human to be paying attention at the right second, which is exactly the property a machine-speed environment demands on both sides of the fence.
Frequently asked questions
01What happened in the DIVD Zammad AI agent breach?
On September 21, 2026, an autonomous AI agent chained two zero-day flaws in the Zammad helpdesk platform to breach the Dutch Institute for Vulnerability Disclosure, reaching root access in seconds. Public coverage began October 1, 2026.
02What are CVE-2026-102489 and CVE-2026-102490?
CVE-2026-102489 is an unauthenticated remote code execution flaw in Zammad versions 6.3.0 through 6.5.4. CVE-2026-102490 is a privilege escalation flaw to root affecting every Zammad version, including the latest alpha release. DIVD says neither flaw has a fix yet.
03Why was DIVD targeted by an AI agent?
DIVD used Zammad internally for its own ticketing. No public reporting confirms why this specific nonprofit was chosen; part of what makes the incident notable is that a vulnerability-disclosure organization was not previously treated as a high-risk target.
04How did the AI agent's mistakes help DIVD investigate the breach?
The agent polluted its own man-in-the-middle position by running password spraying through it, and left highly verbose self-commentary on its own actions. DIVD says that overexplaining made reverse-engineering the attack easier afterward.
05Does TLM Forge prevent attacks like the DIVD breach?
No. TLM Forge is a spec-audit and code-review governance tool for teams building with AI coding agents, gating merges before deployment. It is not an intrusion-detection or incident-response product and does not monitor running systems.