OffPerimeter · Threat advisories
Campaign advisory
lowPublished 2026-10-01 · 0 indicators

JSP webshells deployed via CVE-2026-73570 exploitation in Zimbra Collaboration Suite

Threat actors are exploiting CVE-2026-73570, an OS command injection vulnerability in Zimbra Collaboration Suite, to gain unauthorized access. The attack chain includes out-of-band scanning, the deployment of multiple JSP webshells, and privilege escalation to root. Once access is established, attackers exfiltrate authentication secrets and maintain persistence using a custom systemd service.

ShareXLinkedInWhatsApp
First seen
2026-07-28
Last seen
2026-10-01
Threat actors
—
Malware
JSP webshells
Sectors
Technology
Countries
—

How it works

The attack begins with out-of-band scanning to probe for the vulnerable injection point in Zimbra Collaboration Suite. Attackers then exploit CVE-2026-73570 via specially crafted SMTP requests to achieve remote code execution. Following initial access, JSP webshells are deployed to application directories to facilitate command execution via wget or curl. The actors escalate privileges to root, exfiltrate authentication secrets, and establish persistence by deploying a systemd service named zimlog.service.

Techniques (MITRE ATT&CK)

What to do

References

ShareXLinkedInWhatsApp