bleeping-computer · Crawled Jul 10, 2026
Zimbra urges customers to patch critical web client XSS flaw
4 Actors 2 CVEs
Read original article ↗
AI Summary
Zimbra has urged customers to patch a critical stored cross-site scripting (XSS) vulnerability in its Classic Web Client, which could allow attackers to execute malicious code via specially crafted emails. The flaw affects Zimbra Collaboration Suite users and could lead to theft of session data, account settings, or mailbox contents. Although no CVE has been assigned yet, the vulnerability was reported by Google's Threat Analysis Group and is suspected to be exploited by state-backed actors, particularly Russian-linked groups.
AI-extracted · verify before operational use
Extracted Entities 6 found
MITRE ATT&CK TTPs 52 techniques
T1059.001 PowerShell · Execution T1003 OS Credential Dumping · Credential Access T1021.001 Remote Desktop Protocol · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1036 Masquerading · Defense Evasion T1036.005 Match Legitimate Name or Location · Defense Evasion T1053.005 Scheduled Task · Execution T1055 Process Injection · Defense Evasion T1055.001 Dynamic-link Library Injection · Defense Evasion T1056.001 Keylogging · Collection T1059.003 Windows Command Shell · Execution T1070.004 File Deletion · Defense Evasion T1071.001 Web Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1090 Proxy · Command And Control T1105 Ingress Tool Transfer · Command And Control T1110 Brute Force · Credential Access T1133 External Remote Services · Persistence T1136.001 Local Account · Persistence T1185 Browser Session Hijacking · Collection T1204.002 Malicious File · Execution T1556 Modify Authentication Process · Credential Access T1558 Steal or Forge Kerberos Tickets · Credential Access T1566 Phishing · Initial Access T1566.001 Spearphishing Attachment · Initial Access T1586 Compromise Accounts · Resource Development T1684.001 T1684.001 T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1098 Account Manipulation · Persistence T1114 Email Collection · Collection T1555 Credentials from Password Stores · Credential Access T1570 Lateral Tool Transfer · Lateral Movement T1588 Obtain Capabilities · Resource Development T1071.004 DNS · Command And Control T1078.004 Cloud Accounts · Defense Evasion T1556.005 Reversible Encryption · Credential Access T1558.003 Kerberoasting · Credential Access T1003.001 LSASS Memory · Credential Access T1021.003 Distributed Component Object Model · Lateral Movement T1071 Application Layer Protocol · Command And Control T1071.003 Mail Protocols · Command And Control T1074.001 Local Data Staging · Collection T1132.002 Non-Standard Encoding · Command And Control T1190 Exploit Public-Facing Application · Initial Access T1203 Exploitation for Client Execution · Execution T1485 Data Destruction · Impact T1496 Resource Hijacking · Impact T1530 Data from Cloud Storage · Collection T1539 Steal Web Session Cookie · Credential Access T1552 Unsecured Credentials · Credential Access T1557 Adversary-in-the-Middle · Credential Access