JSP webshells deployed via CVE-2026-73570 exploitation in Zimbra Collaboration Suite
Threat actors are exploiting CVE-2026-73570, an OS command injection vulnerability in Zimbra Collaboration Suite, to gain unauthorized access. The attack chain includes out-of-band scanning, the deployment of multiple JSP webshells, and privilege escalation to root. Once access is established, attackers exfiltrate authentication secrets and maintain persistence using a custom systemd service.
- First seen
- 2026-07-28
- Last seen
- 2026-10-01
- Threat actors
- —
- Malware
- JSP webshells
- Sectors
- Technology
- Countries
- —
How it works
The attack begins with out-of-band scanning to probe for the vulnerable injection point in Zimbra Collaboration Suite. Attackers then exploit CVE-2026-73570 via specially crafted SMTP requests to achieve remote code execution. Following initial access, JSP webshells are deployed to application directories to facilitate command execution via wget or curl. The actors escalate privileges to root, exfiltrate authentication secrets, and establish persistence by deploying a systemd service named zimlog.service.
Techniques (MITRE ATT&CK)
- T1595 · reconnaissanceActive ScanningMicrosoft observed two distinct out-of-band scanning tools probing the vulnerable injection point.
- T1059 · executionCommand and Scripting InterpreterThe attackers deployed JSP webshells to publicly accessible application directories and executed content through wget or curl.
- T1543.003 · persistenceWindows ServiceA secondary persistence mechanism was deployed using a systemd service named zimlog.service.
- T1555 · credential_accessCredentials from Password StoresAttackers targeted Zimbra's centralized service and authentication secrets for credential exfiltration.
- T1095 · command_and_controlNon-Application Layer ProtocolThe actors used HTTP and HTTPS callbacks to validate command execution.
What to do
- Update Zimbra Collaboration Suite to version 10.1.20 or later immediately.
- Uninstall the optional zimbra-snmp package if it is not required for operations.
- Audit application directories for unauthorized JSP webshells.
- Check for the presence of a systemd service named 'zimlog.service'.
- Restrict SNMP and SMTP access to trusted networks.