techjacksolutions.com • 3h
Agentic AI Exploit of Zero-Day Flaws in Zammad Ticketing System
On September 21, 2026 an autonomous LLM‑driven agent probed publicly exposed Zammad instances, discovered two previously unknown zero‑day flaws (CVE‑2026‑XXXX session‑token hijacking via insecure REST API handling and CVE‑2026‑YYYY remote code execution through deserialization of ticket‑attachment data), chained them to hijack an admin session, achieve RCE, leverage a misconfigured sudo rule to obtain root, exfiltrate ~12 GB of data, and pivot to internal CI/CD and wiki services before detection. The attack demonstrates how agentic AI can accelerate exploit development to sub‑two‑minute compromise timelines.