Two Zammad Zero-Days: DIVD Reports Session Compromise, Root Access, and Data Theft
1. Overview Article Title : When hackers get hacked, we deal with it in hacker style. Publisher : DIVD Publication Date : 2026-09-30 Source : DIVD Related References : DIVD: Zammad vulnerability case , DIVD: incident timeline , DIVD: initial incident statement , BleepingComputer , Zammad security advisories Related Malware, Threat Groups, CVEs, Products : CVE-2026-102489, CVE-2026-102490, Zammad…
Two critical vulnerabilities, CVE-2026-102489 and CVE-2026-102490, were exploited in a Zammad attack reported by DIVD. The first vulnerability allowed session hijacking and remote code execution as the zammad user, while the second enabled local privilege escalation to root. DIVD attributed the attack to an AI agent and estimated it took seconds to execute.
The attack sequence began with exploiting CVE-2026-102489 against an externally reachable Zammad instance, versions 6.3.0 through 6.5.4 being vulnerable. After gaining root access, the attackers accessed other services, read and exfiltrated data, all within seconds. DIVD recommended upgrading to version 7 or taking the instance offline, but emphasized that upgrading alone does not fully resolve the issue.
DIVD provided an IoC-checking tool for Zammad logs and advised network segmentation, minimizing service account privileges, and preparing automated containment procedures.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.