BREAKING NEWSBREAKING: ASOS Confirms Customer Data May Have Been Accessed in Cyber Incident
Monitoring active · Brevard County, Florida

A3E Cyber Blog

Zammad Zero-Days Exploited in DIVD Breach: What Businesses Should Do

Two Zammad zero-days were exploited in a confirmed breach of the Dutch Institute for Vulnerability Disclosure, or DIVD. The organization said attackers chained the flaws to hijack a user session, execute code as the Zammad service account, and then escalate privileges to root.

DIVD detected the intrusion on September 22, 2026, blocked access to systems in its data center, and began an incident response investigation. The organization has confirmed that attackers accessed other services and read or exfiltrated data, but the full impact is still being determined.

What happened in the Zammad zero-day attack

Zammad is an open-source help-desk and customer-support platform. It often contains customer messages, attachments, employee conversations, account details, and links to other business systems, making it a valuable target when exposed to the internet.

According to DIVD, the attackers first abused CVE-2026-102489 to hijack an authenticated Zammad session and gain remote code execution as the Zammad user. They then used CVE-2026-102490, a local privilege-escalation vulnerability, to obtain root access.

DIVD traced the first malicious access to September 21. The organization detected suspicious activity the following day, isolated its data-center systems, and started an investigation with incident response firm Merlon Security. DIVD reported the vulnerabilities to Zammad on September 24 and began scanning for and notifying vulnerable system owners on September 26.

What is confirmed

  • The DIVD breach is confirmed. DIVD has publicly stated that attackers entered through two previously unknown Zammad vulnerabilities.
  • The exploit chain reached root access. The flaws allowed session hijacking, remote code execution, and local privilege escalation.
  • Data was accessed. DIVD said the attackers reached other services and read or exfiltrated data.
  • A patch is available. DIVD recommends upgrading to Zammad 7 and says there is no workaround for the affected software.
  • The investigation remains active. DIVD is continuing to assess the extent of the incident and the affected data.

What remains unverified

DIVD has not yet published a complete inventory of the data taken, the number of people affected, or the identity and affiliation of the attacker. Those details should not be treated as established until the investigation produces additional evidence.

The public information confirms exploitation against DIVD, but it does not establish that every vulnerable Zammad server has been attacked. DIVD is scanning for vulnerable instances and notifying their owners, which indicates that organizations should act quickly without assuming that compromise is universal.

Which Zammad versions are affected

DIVD reports that CVE-2026-102489 affects Zammad versions 6.3.0 through 6.5.4. The same flaw exists in versions 7.0.0 through 7.1.3, although DIVD says environmental conditions prevent exploitation in those releases.

CVE-2026-102490 affects versions from 1.5.0 through 7.1.0-alpha and can allow the Zammad service account to escalate privileges to root. Because the vulnerabilities can be chained and no workaround is available, DIVD advises users to move to a current Zammad 7 release.

Businesses using a hosted Zammad service should confirm the provider’s patch status and ask whether the provider has reviewed logs for signs of exploitation.

Why this incident matters to small businesses

Help-desk systems are frequently trusted repositories for sensitive operational information. Tickets may contain customer data, password-reset discussions, screenshots, configuration files, invoices, contracts, and internal troubleshooting notes. Compromise can also expose integration credentials or create a path toward connected systems.

The incident also shows how quickly an attacker can move after gaining an initial foothold. DIVD said the exploit chain progressed from a hijacked session to root access within seconds. Strong network segmentation helped limit deeper movement, but it did not prevent data access.

Practical defensive actions

1. Upgrade Zammad or take the service offline

Install a current Zammad 7 release as the first priority. If an affected system cannot be updated immediately, remove it from public access and consider taking it offline until it can be secured. DIVD states that no workaround is available.

2. Check logs and preserve evidence

Use DIVD’s published verification script and review Zammad, web-server, authentication, and operating-system logs for indicators associated with the exploit chain. Preserve relevant logs and disk snapshots before making broad cleanup changes if compromise is suspected.

3. Invalidate sessions and rotate credentials

Terminate active Zammad sessions and rotate credentials that may have been stored in tickets, configuration files, environment variables, or integrations. Include API tokens, email credentials, single sign-on secrets, and service-account keys.

4. Review integrations and connected systems

Identify every system Zammad can reach, including email, identity providers, customer databases, chat tools, monitoring platforms, and automation services. Review those systems for unusual logins, token use, permission changes, and data transfers.

5. Segment customer-support infrastructure

Restrict the help-desk server’s network access to only the services it needs. Administrative interfaces should not be broadly exposed, and outbound connections should be filtered where practical. Segmentation can reduce the damage if an application is compromised.

6. Review data-exfiltration indicators

Examine outbound traffic, large downloads, archive creation, new scheduled tasks, unexpected processes, and access to sensitive ticket queues. A clean vulnerability scan does not prove that a system was not previously compromised.

What to do if compromise is suspected

Disconnect the affected server from the network without destroying evidence, activate the incident response plan, and contact a qualified security provider. Determine what data and credentials were accessible, notify affected partners or customers when required, and follow applicable breach-reporting laws and contractual obligations.

Organizations should continue monitoring DIVD and Zammad advisories as the investigation develops. New indicators or impact details may change the scope of required response actions.

Sources

Next step

Want this checked on your own systems?

The assessment is free and the summary is yours to keep either way.

Leave a comment

Your email address will not be published. Required fields are marked *

Call now Book an assessment