Sentrix

Field notes · Exposure

Zammad and TeamCity: IT tools as the way in

A Zammad help desk breached at DIVD, a TeamCity flaw used by ransomware: the IT team's own tools hold the keys to everything. What to do, MSP angle.

By Sentrix · Published 2026-10-05

On September 21, 2026, someone broke into the network of the Dutch Institute for Vulnerability Disclosure (DIVD) through its Zammad help desk. Two days later, on September 23, CISA flagged that a JetBrains TeamCity flaw was now being used in ransomware campaigns. A ticketing system and a continuous integration server: two tools the IT team installs for itself, and that hold the keys to everything else.

What the sources say

DIVD, on its own breach. The organisation published its own case, DIVD-2026-00014, with a final statement on October 1. The attackers chained two unknown Zammad flaws to hijack a session, run code, then move from the zammad user to root. They then reached other services and exfiltrated data, including DIVD email addresses of volunteers and possibly contact details. DIVD writes: "The modus operandi indicates an agentic AI powered attack, something we had not seen before," and notes that the scripts contain passages where "the agent justifies its own actions." It credits network segmentation and a fast response for limiting the damage.

The two flaws. Case DIVD-2026-00015 describes CVE-2026-102489, a session hijack leading to code execution as the zammad user (versions 6.3.0 to 6.5.4), and CVE-2026-102490, a local privilege escalation to root (v1.5.0 to v7.1.0-alpha). The timeline is tight: exploited on the 21st, analysed and reproduced on the 22nd and 23rd, reported to Zammad on the 24th, limited disclosure and victim notifications from the 26th. Zammad asks users to move to version 7.2.0 and keep server access to trusted administrators. CISA added both CVEs to its KEV catalog on October 2.

TeamCity. CVE-2026-63077, rated 9.8, lets an unauthenticated attacker run commands on a TeamCity On-Premises server through unsafe deserialisation in the agent polling protocol. JetBrains fixed it on July 25 in versions 2025.11.7 and 2026.1.3. It entered the KEV catalog on August 5, and CISA said on September 23 that it is exploited in ransomware campaigns.

Why it matters

A help desk and a build server are not production systems in the usual sense, which is exactly why they often slip out of the patch cycle. Yet the first keeps conversations, attachments and sometimes credentials sent by users; the second holds deployment secrets and produces what goes to production.

For a managed service provider (MSP) or managed security service provider (MSSP), the effect multiplies: the same ticketing system, the same pipeline and the same remote access tool serve every client. One compromised tool gives a view, sometimes access, into each of them.

The second lesson is speed. DIVD investigated, reported and disclosed within five days, which is exemplary. But if the attacker is automated, as the organisation believes, chaining two flaws up to root takes minutes. For TeamCity, more than two months separated the fix from its use by ransomware: the time was there, and not everyone took it.

What we think at Sentrix

  1. Put the IT team's tools on the inventory of exposed assets. Ticketing, continuous integration, configuration management, remote access, password vaults: each with its version, its internet exposure and an owner. That is the inventory the CTEM continuous exposure module keeps current, see the five stages of CTEM.
  2. Patch on KEV listing, not on the monthly cycle. A catalog entry triggers the decision the same day, with a measurable deadline, as our vulnerability and patch management service describes.
  3. Take these tools off the internet. A help desk can keep a public portal while restricting administration and the server to a trusted network.
  4. Segment. That is what limited the damage at DIVD: the help desk must not see the rest of the network or the clients' environments.
  5. Treat pipeline secrets as identities. Deployment tokens and service accounts are inventoried, scoped and rotated, as our article on non-human identities and our identity and access service explain.
  6. Never let a client password travel in a ticket. A shared vault with an access log replaces it.

The next step

List today the tools your IT team runs for itself, with, for each one, its version, its internet exposure and what it can reach. The rows without an answer are your priority for the week. If you want to do this exercise with us, contact us.

Sources

Frequently asked questions

Q01
Which Zammad versions need fixing?
CVE-2026-102489, the session hijack that leads to code execution, affects Zammad 6.3.0 to 6.5.4; the flawed code is also in 7.0.0 to 7.1.3 but not exploitable there in practice. CVE-2026-102490, the local privilege escalation to root, affects v1.5.0 to v7.1.0-alpha. Zammad recommends upgrading to 7.2.0 and restricting server access to trusted administrators. DIVD adds: upgrade, or take the instance offline.
Q02
Why is a managed service provider more exposed?
Because its internal tools serve all of its clients at once. A ticketing system holds conversations, attachments and sometimes credentials sent by clients; a continuous integration server holds deployment secrets; a remote access tool opens the endpoints. Compromising one of them gives a view, or even access, into every client. It is an inventory to keep, just like the clients' exposed systems.
Q03
Was the attack against DIVD run by an AI?
DIVD writes that the modus operandi indicates an agentic AI powered attack, a first for the organisation, and that the scripts contained notes in which the agent justifies its own actions. Whatever the tool, the practical lesson is speed: an automated attacker chains flaws in minutes. Segmentation and detection that alerts fast matter more than ever, because a monthly patch cycle arrives too late.

Let's talk about your compliance program.

Last updated: 2026-10-05