{
  "id": 11212014,
  "title": "Two Zammad Zero-Days: DIVD Reports Session Compromise, Root Access, and Data Theft",
  "url": "https://urgent.news/2026/10/01/two-zammad-zero-days-divd-reports-session-compromise-root-access-and",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-01T14:36:06.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/anoymask/two-zammad-zero-days-divd-reports-session-compromise-root-access-and-data-theft-f21"
  },
  "original_language": "en",
  "account": "Two critical vulnerabilities, CVE-2026-102489 and CVE-2026-102490, were exploited in a Zammad attack reported by DIVD. The first vulnerability allowed session hijacking and remote code execution as the zammad user, while the second enabled local privilege escalation to root. DIVD attributed the attack to an AI agent and estimated it took seconds to execute. The attack sequence began with exploiting CVE-2026-102489 against an externally reachable Zammad instance, versions 6.3.0 through 6.5.4 being vulnerable. After gaining root access, the attackers accessed other services, read and exfiltrated data, all within seconds. DIVD recommended upgrading to version 7 or taking the instance offline, but emphasized that upgrading alone does not fully resolve the issue. DIVD provided an IoC-checking tool for Zammad logs and advised network segmentation, minimizing service account privileges, and preparing automated containment procedures.",
  "summary": "1. Overview Article Title : When hackers get hacked, we deal with it in hacker style. Publisher : DIVD Publication Date : 2026-09-30 Source : DIVD Related References : DIVD: Zammad vulnerability case , DIVD: incident timeline , DIVD: initial incident statement , BleepingComputer , Zammad security advisories Related Malware, Threat Groups, CVEs, Products : CVE-2026-102489, CVE-2026-102490, Zammad…",
  "key_points": [
    "Two critical Zammad vulnerabilities exploited in AI-driven attack",
    "Session hijacking and root access achieved within seconds",
    "DIVD advises upgrading or isolating affected Zammad instances"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}