The Security Organization Compromised by Its Own Threat Class
On September 21, 2026, the Dutch Institute for Vulnerability Disclosure suffered a breach that carried a structural irony no defender wants to face. DIVD exists to identify, disclose, and coordinate remediation of software vulnerabilities. It was compromised by an autonomous AI agent exploiting two zero-day flaws in the very platform DIVD used to manage its disclosure workflow.
This is the first publicly documented case of an agentic AI-powered attack against a security organization. The implications extend far beyond one incident.
Two Zero-Days, Chained in Seconds
The attackers exploited two zero-day vulnerabilities in Zammad, the open-source ticketing platform DIVD used internally. The first, CVE-2026-102489 (CVSS 9.4), is a session hijack vulnerability that enables unauthenticated remote code execution as the Zammad service account. The second, CVE-2026-102490 (CVSS 9.4), is a local privilege escalation flaw that allows the Zammad user to reach root.
Chained together, they gave the attacker full control of the host in seconds. Not minutes. Seconds. The speed was a direct consequence of the attack method: an autonomous agent that decided each step itself, without waiting for human instruction.
Loud, Messy, and Self-Documenting
DIVD’s forensic investigation produced observations that distinguish this from conventional intrusions. The organization described the attack as “loud and very, very messy,” with the agent working at automated speed on what DIVD characterized as “sloppy logic.” Most striking: the agent left explanatory code comments justifying its own actions after every step — something a human attacker would not bother to do.
“We could see the agent working automated, because after every action it decided the next step itself, at the speed of light and sloppy logic or pattern,” DIVD stated in a September 28 update. The agent also “skipped a few steps on its learning curve,” including polluting its own man-in-the-middle attack with password spraying — a mistake that reflects automated decision-making rather than human tradecraft.
What Got Out
The breach exposed volunteer data, including DIVD email addresses and contact details. Network segmentation prevented the agent from reaching deeper into DIVD’s infrastructure, limiting the blast radius. DIVD described stopping the attackers as “a win” given the circumstances, while acknowledging that some damage was already done.
The Zammad attack surface is significant: the platform is used by more than 2,000 organizations and approximately 55,000 users globally. CVE-2026-102489 affects versions 6.3.0 through 6.5.4 (exploitable) and 7.0.0 through 7.1.3 (present but not exploitable due to environmental conditions). CVE-2026-102490 affects all tested versions from 1.5.0 through 7.1.0-alpha, though Zammad GmbH has disputed the scope pending further technical details. No official patch exists for CVE-2026-102490; upgrading to Zammad 7.2.0 addresses CVE-2026-102489.
The Trust-Through-Defaults Gap
This breach fits a pattern our recent coverage has traced across multiple identity-layer failures. The Agent Identity Layer Risk synthesis connected Zimbra signing key harvesting, Bouncy Castle MLS credential binding failures, ZITADEL authentication bypasses, and MCP OAuth credential theft into one structural narrative: systems that accept the presence of a credential as sufficient proof of identity, without verifying the binding between key and authorized entity.
The DIVD breach extends that pattern into the development infrastructure layer. Zammad, as a ticketing platform, sits at the operational backbone of vulnerability coordination. When the platform that manages security disclosures has unauthenticated RCE and local privilege escalation, the disclosure process itself inherits that exposure. The trust-through-defaults gap here is not in a cryptographic primitive — it is in the assumption that internal tooling does not need the same adversarial scrutiny as internet-facing infrastructure.
Federal Deadline: October 16
CISA added both CVEs to its Known Exploited Vulnerabilities catalog on October 2, 2026. Under BOD 26-04, federal civilian agencies have 14 days from KEV addition to remediate — making October 16 the mandatory deadline.
DIVD is actively scanning for vulnerable Zammad instances and notifying owners. The organization has published a verification script to help security teams hunt for indicators of compromise. For organizations running Zammad, the immediate actions are: upgrade to version 7.2.0 or later to address CVE-2026-102489, restrict local access to the Zammad host to mitigate CVE-2026-102490, and hunt for signs of the attack chain DIVD has documented.
The Speed Gap Is the Story
Google’s Threat Intelligence Group has reported that vulnerability disclosures doubled between January and August 2026, rising from 5,045 to 10,740 per month. AI-assisted discovery is finding proportionally more remote code execution vulnerabilities than traditional methods. The DIVD breach demonstrates the other side of that equation: not just faster discovery, but faster exploitation by autonomous agents that need no human in the loop.
The agent that breached DIVD was “loud and very, very messy.” The next one may not be.
