Canadian Cyber Security Journal
SOCIAL:
Filed under: Featured, TechTalk

AI Agent Chains Two Zammad Zero-Days to Breach a Dutch Security Nonprofit: What Canadian Teams Should Check

What Happened

The Dutch Institute for Vulnerability Disclosure (DIVD) confirmed an agentic AI system breached its Zammad helpdesk on September 21. The attacker chained two zero-day flaws. CVE-2026-102489 (CVSS 9.4) gives an unauthenticated attacker remote code execution and session leakage in Zammad 6.3.0 through 6.5.4. CVE-2026-102490 (CVSS 9.4) lifts a low-privilege user to root and affects all versions.

Together, the flaws let the agent hijack sessions, run code, and take root in seconds. DIVD says network segmentation stopped the attacker from moving deeper, but data left the system. Observers called the agent sloppy, since it sprayed passwords during its own man-in-the-middle step. It still finished the job. Read the reports from SecurityWeek and Help Net Security.

Why This Matters for Canadian Organizations

Speed is the story. An automated agent went from first contact to root without a human pausing to plan. Patch windows measured in days offer little cover against this tempo.

No Canadian victims have been reported. Helpdesk platforms still deserve attention here. Tickets hold employee details, customer records, screenshots, and password reset links. A Canadian school board, municipality, credit union, or clinic running self-hosted Zammad stores personal information. A breach brings PIPEDA reporting duties, or Quebec Law 25 obligations in Quebec. Federally regulated financial institutions also answer to OSFI Guideline B-13 for open-source and third-party components. Open-source helpdesk tools often sit outside the central patch inventory. Check yours.

What to Do

Inventory every Zammad instance, including ones teams stood up without IT approval. Upgrade to version 7 or take the instance offline, as DIVD advises. Run DIVD’s verification script and review logs for odd session activity and new root-level processes. Rotate credentials and API tokens stored in or reachable from the helpdesk. Keep the helpdesk host segmented from core systems, as DIVD did. Treat any exposed instance as breached until the checks say otherwise.

More technical breakdowns live in our TechTalk section, and daily updates sit in News.

Enjoy this article? Don’t forget to share.