Dutch Institute for Vulnerability Disclosure Breached via Zammad 0-Days
The Dutch Institute for Vulnerability Disclosure (DIVD) has confirmed that attackers breached its infrastructure through two previously unknown vulnerabilities in Zammad, the open-source customer-support and ticketing platform used by its incident-response team.
The attackers first breached DIVD’s systems on September 21, 2026. DIVD detected suspicious activity the following day, blocked access to its data-centre infrastructure and began a forensic investigation with incident-response company Merlon Security.
According to DIVD’s investigation, the attackers chained two Zammad vulnerabilities to hijack a session, remotely execute code as the local zammad user and then elevate their privileges to root. This gave them access to other services and allowed information to be exfiltrated.
The first vulnerability, tracked as CVE-2026-102489, carries a CVSS score of 8.7. DIVD said it affects Zammad versions 6.3.0 through 6.5.4. The underlying vulnerable code is also present in versions 7.0.0 through 7.1.3, but DIVD said environmental conditions prevent exploitation...
Copyright of this story solely belongs to hackread.com. To see the full text click HERE