Zammad Zero-Day Chain Lets AI Agent Hijack Sessions, Execute Code and Escalate to Root

An AI agent breached the Dutch Institute for Vulnerability Disclosure by chaining two previously unknown flaws in Zammad, an open source helpdesk platform. The September 21, 2026 attack moved from a hijacked session to root access, giving the intruder full control of the server within seconds. DIVD detected the intrusion the following day and blocked […]

This article has been indexed from Cyber Security News

Read the original article: