SOCLYDE logo
Current languageEN
Cybersecurity newsData breachSecurity incident

Divd: zammad flaws exploited in an intrusion

DIVD links its intrusion to two Zammad zero-days and confirms volunteer contact details were exposed.

By Soclyde Team

A technician reviews incident response notes in a workroom after a computer intrusion

In summary

  • DIVD says initial access to its systems dates to September 21, 2026, and malicious activity was detected on September 22.
  • On September 30, the organisation linked the intrusion to CVE-2026-102489 and CVE-2026-102490, two Zammad flaws exploited together.
  • On October 1, DIVD confirmed volunteer email addresses and possibly other contact details had left its systems; the exact scope remains under investigation.

Explore next

Soclyde resources

Article contents

The Dutch Institute for Vulnerability Disclosure (DIVD), a coordinated vulnerability disclosure organisation, announced an intrusion into its own systems on September 24, 2026. It blocked access to its infrastructure and began an investigation with an external response team. Its DIVD-2026-00014 case remains open.

DIVD dates the first malicious access to September 21 and detection to the following day. It later identified two zero-day flaws in its Zammad support software as the entry point. These dates and conclusions reflect the organisation’s published investigation and may be supplemented by later updates.

Two Zammad flaws combined

DIVD links the intrusion to CVE-2026-102489 and CVE-2026-102490. Its case file says the flaws were combined to hijack a session, execute code remotely and move from a Zammad user account to root privileges. DIVD describes this progression as taking place within seconds.

The vulnerabilities also prompted a separate DIVD case, DIVD-2026-00015, to notify potentially exposed organisations. Administrators should check Zammad’s advisory for affected versions and applicable fixes, then determine whether their instance is exposed to the internet.

What data left DIVD

On October 1, DIVD confirmed that volunteer data had left its systems, including email addresses and possibly other contact details. It has not yet established exactly whose data or which details were affected. The organisation warns that this information could make it easier to impersonate a volunteer.

DIVD also says the intrusion enabled access to other services and data exfiltration, but it has not published a final, complete inventory. It reports other signs of compromise that remain under review. Network segmentation and its teams’ response are said to have prevented deeper movement through the network.

What DIVD says about the AI agent

DIVD assesses that the modus operandi indicates an attack carried out with an artificial intelligence agent. It published redacted log screenshots that, in its view, show automated scripts justifying their own actions. This is DIVD’s assessment; it is not independent attribution of the operator or the tool.

The organisation says its forensic investigation is ongoing and it cannot yet fully describe the incident’s scope. The case file therefore does not establish that all accessible data was retrieved or publicly identify the person behind the attack.

Steps for affected teams

Zammad operators should check the vendor advisories, apply official fixes or mitigations, and review authentication logs, privileged accounts and activity launched by the application. If the instance could reach mailboxes, databases or integration tokens, assess those paths and rotate secrets after containment.

DIVD volunteers and people communicating with the organisation should verify unexpected messages through a known address, especially if they request a code, document or urgent action. DIVD has provided an official contact address for checking suspicious messages.

The Soclyde connection

A support instance may hold or reach credentials used by a team. Soclyde does not protect Zammad and cannot remediate this intrusion. Its encrypted local-first vault helps users organise passwords and access details on their devices; application permissions, network segmentation and incident response must be handled in the affected environment.

Takeaway

DIVD links the intrusion to two Zammad flaws and confirms volunteer email addresses left its systems, while the full scope remains under investigation. The AI-agent hypothesis is DIVD’s assessment, which it says is supported by redacted log material it published.

If you use Zammad, follow the vendor advisory and look for unusual activity. To reduce password sprawl across a team, see our guide to local-first password managers.

Frequently asked questions

What volunteer data was exposed?

DIVD confirms that volunteer email addresses left its systems and says other contact details may also be involved. It is still investigating exactly whose data and which details were affected. It advises checking unusual messages that appear to come from a volunteer through an official channel.

How did the attackers get in?

DIVD attributes initial access to two Zammad zero-days, CVE-2026-102489 and CVE-2026-102490. Its case file says the combination enabled session hijacking, remote code execution and privilege escalation.

Is the AI-agent attack confirmed?

DIVD says its analysis of scripts and logs indicates agentic behaviour. It has published redacted log screenshots, but the investigation is ongoing; attribute this assessment to DIVD.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading