Hackers have been actively exploiting a critical vulnerability in the Zimbra Collaboration Suite to steal email backups and authentication credentials from vulnerable organizations, Microsoft warned on Wednesday, days after researchers confirmed that hundreds of internet-facing mail servers have already been compromised.

The flaw, tracked as CVE-2026-73570, allows attackers to remotely execute operating system commands without authentication — a command injection bug that effectively hands an intruder a foothold on the mail server itself. Zimbra maintainer Synacor issued a patch on July 20, but did not publicly disclose the vulnerability for more than three weeks afterward, a window that security researchers say gave attackers ample time to reverse-engineer the fix and begin scanning for unpatched systems.

Scale of the compromise

The security-focused Shadowserver Foundation said last week that its scans identified 274 separate Zimbra Collaboration Suite instances that had been compromised. The organization's telemetry also shows how quickly the exposed population is shrinking — a pattern that typically reflects a mix of emergency patching, takedowns and abandonment by administrators who cannot secure their deployments.

  • About 19,000 Zimbra servers were observed in the week following the patch.
  • That figure fell to roughly 12,000 in the weeks after.
  • Shadowserver is currently tracking about 10,000 instances.

The decline matters because it cuts both ways. Fewer exposed servers reduce the pool of easy targets, but the residual population is likely to include systems that are difficult or impossible to patch — legacy deployments, appliances managed by third parties, and mail servers run by small organizations without dedicated security staff.

How the attacks unfolded

According to Microsoft, between July 28 and August 7 its researchers detected two distinct scanning tools probing the Internet for vulnerable endpoints. The attackers first validated that their exploit worked by sending HTTP requests alongside DNS, ICMP and out-of-band identity checks to domains hosted on public services. Those probes allowed the attackers to confirm that the exploit successfully executed commands on vulnerable servers without actually compromising them — a reconnaissance technique designed to separate working targets from dead ends before committing to an intrusion.

Microsoft said its researchers detected “two distinct scanning tools probing the Internet for vulnerable endpoints.”

Eventually, the attackers began using their command injection capability to install malicious payloads, a progression consistent with an operation moving from validation to monetization. Coverage from The Hacker News described the endgame in blunter terms: attackers using the flaw to deploy web shells and harvest authentication secrets — the kind of access that enables persistent re-entry even after a server is patched.

Competing framings of the same story

The incident has produced notably different headlines across the security press, each emphasizing a different phase of the attack chain. Ars Technica led with the theft of email backups and credentials, framing the campaign as a data-loss event for the organizations involved. Betanews emphasized the tally of victims and characterized the bug as an SNMP-related flaw, highlighting the 274 compromised mail servers as the headline number. The Hacker News focused on the mechanics of persistence — web shells and credential harvesting — while Help Net Security folded the campaign into a broader weekly roundup that also flagged exploitation of a previously patched Citrix NetScaler flaw, positioning Zimbra as one incident in a wider wave of n-day exploitation. Those distinctions are not trivial: they shape whether defenders prioritize data-breach response, patch management or threat hunting.

Zimbra's long history as a target

The campaign is the latest in a multi-year pattern of attackers treating Zimbra as a high-value target. Because the platform hosts email — the de facto identity backbone of most organizations — a single compromised server can yield password-reset links, session tokens, internal correspondence and archived mail. Zimbra's customer base skews toward small and midsize businesses, universities, government agencies and managed service providers, many of whom run the software on-premises without the dedicated security operations teams that large enterprises maintain. Previous Zimbra zero-days have been linked to espionage-motivated intrusions, and the platform's authentication and backup subsystems have repeatedly proven to be the most sensitive components to lose control of.

What organizations should do

Security practitioners are urging administrators to treat the July 20 patch as a minimum requirement rather than a complete fix. Recommended steps include:

  • Apply the Synacor patch immediately and verify the version in use on every instance, including backups and staging servers.
  • Hunt for indicators of compromise, particularly unexpected web shells, new scheduled tasks, and outbound connections to unfamiliar domains.
  • Rotate credentials and authentication secrets for accounts stored on or accessible from the mail server.
  • Assume email backups may have been exfiltrated and audit for data exposure accordingly.
  • Reduce the internet-facing footprint of Zimbra deployments wherever possible.

Shadowserver continues to publish exposure data, and Microsoft's findings suggest the reconnaissance phase has given way to active intrusion. For organizations still running unpatched Zimbra servers, the practical question is no longer whether the flaw will be targeted, but whether compromise has already occurred and gone undetected.