// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-wedgDTG 0600Z
Breach Record

Zammad

DISCLOSED 2026-10-02 · UNPATCHED CVE

The Dutch Institute for Vulnerability Disclosure (DIVD) was targeted in an attack that exploited two zero-day vulnerabilities in the Zammad helpdesk software. The attacker used an agentic AI system to discover and exploit the flaws, compromising DIVD's systems. This incident highlights the emerging threat of AI-driven autonomous attacks against security organizations.

The record

What we know

Disclosed
2026-10-02
Attack vector
Unpatched Cve
Sources

Cited reporting

Similar vector · recent

Other unpatched cve breaches on file

This page is the permanent ColdRecon entry for the Zammad disclosure. It updates if new public reporting emerges. All tracked breaches →

Zammad just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →