Skip to content

AI agent exploits CISA KEV chain: the DIVD Zammad breach explained

3 min read
Share

In early October, the Dutch Institute for Vulnerability Disclosure (DIVD) disclosed that its helpdesk infrastructure was compromised via chained exploitation of two Zammad vulnerabilities: CVE-2026-102489 and CVE-2026-102490. Both carry a CVSS score of 9.4 and were added to the CISA Known Exploited Vulnerabilities catalog on October 2. The FCEB patch deadline was October 5. What distinguishes this incident is how it unfolded: the threat actor used an AI agent to automate both the exploitation chain and lateral movement within the DIVD environment.

The vulnerability chain

CVE-2026-102489 and CVE-2026-102490 form an authentication bypass and privilege escalation chain in Zammad, a widely deployed open-source helpdesk and ticketing platform. When chained, they allow an unauthenticated attacker to gain administrative access and execute commands on the underlying server. Approximately 1,200 organizations worldwide use Zammad for IT service management and support operations, many of which were potentially exposed during the window before patches were applied.

The AI agent in the attack chain

According to the DIVD disclosure, the attacker deployed an AI agent to orchestrate the multi-step exploitation process. Rather than a human manually sequencing authentication bypass, privilege escalation, and lateral movement, the agent automated the full chain in a compressed timeframe. This is one of the first confirmed instances in which an AI-driven attack agent was used to exploit a CISA KEV chain in production infrastructure.

The implications extend beyond Zammad. An AI agent running an attack chain does not pause, fatigue, or make the timing errors a human attacker typically does. Speed and consistency of execution are qualitatively different from what defenders have historically planned for.

Context from the 2026 threat landscape

HiddenLayer's 2026 AI Threat Landscape Report, released this week, finds that 1 in 8 security breaches now involve agentic AI systems, up from near-zero in 2024. CrowdStrike's 2026 Threat Hunting data shows mean adversary breakout time has dropped to 27 minutes from 84 minutes in 2025. The DIVD incident is a concrete case where those trends converge: an AI agent achieved in minutes what would previously have required a skilled attacker spending hours, against a vulnerability that had been public in the CISA KEV for only days before the FCEB deadline.

Immediate action items

Organizations running Zammad should apply vendor patches for CVE-2026-102489 and CVE-2026-102490 immediately. The FCEB patch deadline of October 5 has passed. For organizations that cannot patch immediately, network segmentation of the helpdesk infrastructure and disabling external access to the Zammad admin interface are interim mitigations.

More broadly, this incident warrants a review of detection coverage for AI-assisted attack patterns. Traditional signature-based detection may not flag the rapid, automated sequencing that an AI agent produces. Behavioral anomaly detection on authentication events and privilege escalation in service desk platforms should now be treated as a priority control. The time to detect and respond is measured in minutes, not hours.