Zero‑Day Exploits in Zammad Grant Root Access to Dutch Institute for Vulnerability Disclosure
Two unknown Zammad vulnerabilities were used in an AI‑driven attack that achieved remote code execution and root privileges on the Dutch Institute for Vulnerability Disclosure. The breach highlights the need for continuous third‑party risk monitoring and rapid patch management to satisfy control‑assurance requirements.
ADTP Breach Watch· October 3, 2026· HackRead
SeverityCritical
Type👤 Breach
ConfidenceHigh
ReportedOct 3, 2026
Government & Public SectorGovernment agencies and any organization using Zammad or similar open‑source ticketing platformsVulnerability Exploit
What happened
Attackers leveraged two zero‑day vulnerabilities in the open‑source ticketing system Zammad to execute code remotely and obtain root access on the Dutch Institute for Vulnerability Disclosure’s infrastructure.
Why it matters for trust and compliance
This incident underscores the importance of a control‑assurance program that continuously monitors third‑party software for unpatched flaws and documents remediation actions for audit readiness.
Demonstrates the need for continuous monitoring of third‑party components as evidence of due diligence
Provides a concrete control‑mapping example for patch‑management and vulnerability‑remediation objectives
Who is affected
Government agencies and any organization using Zammad or similar open‑source ticketing platforms
Recommended actions
Identify Zammad version in use and apply any available security patches or mitigations
Integrate Zammad vulnerability monitoring into your third‑party risk program
Update incident‑response playbooks to include zero‑day exploitation scenarios
Get the Breach Digest
The incidents that matter for your vendors and your data, analysed for practitioners, in one email.