The Dutch Institute for Vulnerability Disclosure finds security holes and warns the people who have them. This time it was the victim. DIVD says an autonomous AI agent broke into its network through two flaws nobody knew about, in Zammad, the open-source helpdesk software it uses.

The break-in started on September 21, according to DIVD's case page. The next day the volunteers spotted the activity and cut off access to their data center systems. They published the case on September 30.

Root in seconds

The two flaws, CVE-2026-102489 and CVE-2026-102490, were zero-days, meaning no fix existed when they were used. According to DIVD's statement quoted by BleepingComputer, together they let the attacker take over a session, run its own code and climb from the Zammad user to root, the most powerful account on the server, "in seconds, due to the agentic part of this hack."

DIVD says the agent made its own decisions without a person steering it. It also left behind detailed notes on why it did what it did, which helped DIVD piece the attack together. Who ran the agent is not public.

Splitting the network into separate parts kept the attacker from going deeper, DIVD says. It has not yet said what data was taken, and the investigation with the firm Merlon Security is still open.

What Zammad users should do

Zammad says it has more than 2,000 customers. DIVD tells them to upgrade to version 7 or take their system offline. The Dutch national cyber security center advises installing the updates urgently and saving application and network logs first.