Zammad Zero-Day Vulnerabilities Exploited

Two Zammad zero-day vulnerabilities give attackers root on helpdesk servers. Used against DIVD, on CISA KEV, one flaw had no fix at disclosure.

Two Zammad zero-day vulnerabilities, CVE-2026-102489 and CVE-2026-102490, let an attacker take over the open-source helpdesk and reach root on its server. The Dutch Institute for Vulnerability Disclosure (DIVD) says an automated AI agent chained them against its own network on September 21. CISA has added the first flaw to its Known Exploited Vulnerabilities catalog, and…

Read More

Salesforce Agentforce AI Agent Vulnerability

Salesforce Agentforce AI agent vulnerability let a web form hijack CRM data with zero clicks. Patched already, but the pattern will repeat elsewhere.

A Salesforce Agentforce AI agent vulnerability, publicly disclosed September 24 by research firm Zenity Labs under the name “SalesBleed,” let an attacker plant a hidden instruction in an ordinary sales lead form and later exfiltrate CRM data with zero clicks, once an employee simply asked their AI agent to look at the newest lead. Salesforce…

Read More

Ruflo RufRoot CVE-2026-59726: AI Agents Hijacked

Ruflo RufRoot CVE-2026-59726 (CVSS 10.0) lets attackers hijack AI agents via an unauthenticated MCP bridge exposed to the network by default.

Ruflo RufRoot CVE-2026-59726, a maximum-severity CVSS 10.0 flaw disclosed by Noma Security, lets an unauthenticated attacker take full control of an AI agent platform used by an estimated one million people — through a single HTTP request against a management bridge that ships exposed to the network by default. What Happened Ruflo is an open-source…

Read More

Langflow CVE-2026-55255 KEV: AI Agent Flaw Explained

Langflow CVE-2026-55255 KEV

The Langflow CVE-2026-55255 KEV entry, added by CISA on July 7, marks the first time an AI agent orchestration platform has ever appeared in the Known Exploited Vulnerabilities catalog. The flaw carries a CVSS score of just 6.1 from CISA, yet KEVIntel and CIRCL independently score the same bug 9.9, because it lets an authenticated…

Read More

JADEPUFFER Agentic AI Ransomware Attack

JADEPUFFER agentic AI ransomware

JADEPUFFER agentic AI ransomware is, according to Sysdig’s Threat Research Team, the first publicly documented case of a ransomware attack executed start to finish by an autonomous AI agent — from initial access through a Langflow vulnerability to database encryption and extortion, with no human operator directing any step. What Happened Sysdig identified JADEPUFFER, this…

Read More