The Dutch Institute for Vulnerability Disclosure spends its days scanning the internet, finding holes in other people's software, and politely telling them how to fix it. On September 21, 2026, an autonomous AI agent flipped the script and found the holes in theirs.
Not with a sophisticated supply-chain compromise. Not with a nation-state zero-day arsenal. With two flaws chained in an open-source helpdesk system — and the machine speed of an agent that doesn't wait for a human to press enter.
By the time DIVD's teams caught up, the attacker had root on the box, had reached other internal services, and had read and exfiltrated data. The whole privilege ladder, from unauthenticated stranger to root, took seconds.
When the Vulnerability Hunters Become the Vulnerability
DIVD is a nonprofit of volunteer researchers who notify system owners about flaws before criminals exploit them. Being attacked isn't a shock for them — it comes with the territory. What makes this case different is how the attack ran.
DIVD discovered the intrusion while working an earlier case in which it determined it had been compromised through AI agent activity. Digging into how attackers actually got in, DIVD and its research partner Merlon Security reconstructed the path and identified two previously unknown vulnerabilities in Zammad, the open-source ticketing and helpdesk platform DIVD used internally.
Their write-up on the incident, tracked as DIVD-2026-00015, is blunt about what happened next. As the organization put it: "When hackers get hacked, we deal with it in hacker style."
The Two Zero-Days
The chain is built from two Zammad flaws, both now assigned CVEs:
- CVE-2026-102489 — a session hijacking flaw reachable in Zammad 6.3.0 through 6.5.4. An attacker can hijack legitimate sessions and escalate the defect into remote code execution as the
zammadservice user. (The defect also exists in 7.0.0 through 7.1.3, but environmental conditions block exploitation there.) - CVE-2026-102490 — a local privilege escalation flaw that has existed since version 1.5.0, through 7.1.0-alpha. Once code runs on the host as the service user, this takes the attacker the rest of the way to root.
Each flaw is serious on its own. Chained, they form a straight line: unauthenticated access on a public web endpoint, to RCE, to full root control of the server.
Root in Seconds — the Agentic Speedup
Here's the part that matters for every team running internet-facing software: the speed was the AI agent's signature.
DIVD's disclosure states it plainly. From a Zammad user, to root, in seconds — "due to the agentic part of this hack." The agent analyzed the environment, chained the two vulnerabilities, escalated privileges, and moved to other services without a human directing every step. It made decisions and executed the next move on its own, compressing an attack sequence that historically takes hours of manual work into moments.
After reaching root, the attacker accessed other services, read data, and exfiltrated some of it. Network segmentation and a fast response from DIVD's IT and incident response teams stopped the intrusion before it spread further — but not before some damage was done.
DIVD detected the attack partly because the agent was noisy: it left visible traces that helped investigators reconstruct everything. That's a comfort, but an uncomfortable one. A more disciplined attacker running the same agentic tooling could stay much quieter.
Why a Helpdesk Is a Tier-0 Target
The choice of target vector is worth sitting with. Zammad is popular open-source software — more than 2,000 customers and 55,000 users — and helpdesks are one of the most exposed systems any organization runs.
Think about what lives in a support desk: full name, email, phone numbers, correspondence with external partners, credentials shared in ticket threads, links to internal systems, and a habit of attaching screenshots that were never meant for prying eyes. A helpdesk is a pre-indexed map of your organization, accessible to anyone who can reach the login page.
That's why an RCE chain into a ticketing system is never just a ticketing problem. It's an identity problem, an access problem, and a lateral movement problem, all at once.
What To Do This Week
If your organization runs Zammad in any version, the guidance from DIVD and Zammad is unambiguous:
- Update to Zammad version 7, or take the system offline. Version 7 is considered safe; every older version is presumed exploitable. Don't wait for a patch window — this chain is in CISA's Known Exploited Vulnerabilities catalog.
- Assume prior compromise. The DIVD chain is silent until an attacker does something loud. Hunt the supplied indicators in your logs and look for unexpected sessions, odd user activity in the helpdesk, and any unrecognized local accounts.
- Rotate everything the helpdesk can reach. Tickets routinely carry credentials, tokens, and API keys. Treat anything stored in or sent through the system as potentially exposed.
- Cut the helpdesk out of the trust zone. The only reason this breach stayed contained was segmentation. Your ticketing system should never be a stepping stone from a web form to internal infrastructure.
- Model the machine-speed threat. Run the scenarios your response plan needs to survive when the attacker moves in seconds, not hours: containment decisions, credential rotation, and management comms all rehearsed at that tempo.
The Bigger Picture: Agentic Attacks Have Arrived
For years, AI in security conversations lived in two boxes: AI helping defenders find and patch faster, and AI-generated phishing getting more convincing. The DIVD breach breaks out of both boxes. This was an AI agent performing the entire intrusion chain — reconnaissance, exploitation, privilege escalation, lateral movement — against a real organization, with real consequences.
It also landed on an ironic target. The institute whose core mission is finding vulnerabilities before they're exploited was itself breached through vulnerabilities nobody knew about. Nobody at DIVD was careless; the flaws existed in code thousands of organizations run.
That's the strategic takeaway for our clients across the GCC and beyond: your security posture is only as strong as the least-watched open-source system you've exposed to the internet, and your adversaries now operate at machine speed. Defense still wins — segmentation, rapid response, and aggressive patching contained this in hours — but the window for manual, ticket-driven remediation is shrinking every month.
An AI agent took over a security nonprofit's infrastructure in seconds. The next one may be quieter. Make sure your stack is ready before, not after.
At aratech, we help organizations harden the systems attackers actually target — helpdesks, identity planes, and the AI infrastructure now entering the kill chain on both sides. If your internet-facing stack hasn't been modeled against agentic-speed attacks, that's the first conversation to have.