Data Security

AI agent exploits zero-day flaws in Zammad ticketing system

AI Agent concept with glowing neon interface icons for data cloud settings and sharing representing artificial intelligence and digital network

As outlined in Bleeping Computer, the Dutch Institute for Vulnerability Disclosure (DIVD) has reported a significant network breach facilitated by an autonomous AI agent that exploited two zero-day vulnerabilities in the open-source Zammad ticketing system.

The attack, described as "loud and very, very messy," was executed by an AI agent that operated without human intervention, making its own decisions to navigate and exfiltrate data. The two zero-day flaws, identified as CVE-2026-102489 and CVE-2026-102490, allowed the attacker to hijack sessions, execute remote code, and escalate privileges to root access within seconds. While the threat actor did not penetrate deeper into DIVD's network due to segmentation and incident response, the incident highlights the growing threat of AI-powered attacks. Zammad, a popular helpdesk and support ticketing platform used by over 2,000 organizations, has released version 7 to address these vulnerabilities. DIVD is urging all users to upgrade or take their instances offline immediately.

Source: Bleeping Computer

You can skip this ad in 5 seconds