Hackers have been exploiting a critical flaw in the Zimbra Collaboration Suite email system since late July to steal email backups and sign-in credentials from vulnerable organizations, Microsoft said on Wednesday.

The vulnerability, tracked as CVE-2026-73570, lets an attacker with no credentials run operating-system commands on a server by sending a crafted email aimed at the suite’s SNMP notification path, according to Microsoft’s report. It works only when an optional component, the zimbra-snmp package, is installed and SNMP notifications are switched on. Ars Technica first reported the campaign.

Synacor, which maintains Zimbra, released a patch on July 20 but did not publicly disclose the vulnerability for more than three weeks after that.

Many servers remain exposed. The Shadowserver Foundation, a security group, said last week that its scans had found 274 separate Zimbra instances already compromised. The group counted about 19,000 servers running the software in the week after the patch and roughly 12,000 in the weeks that followed. It is now tracking about 10,000.

Between July 28 and Aug. 7, Microsoft said, it detected two distinct scanning tools probing the internet for vulnerable systems. The attackers first checked that their exploit worked — sending HTTP requests and DNS, ICMP and other out-of-band identity checks to domains hosted on public services, which confirmed that commands ran on the target servers without actually compromising them. Then they moved to installing malicious payloads.

“Following successful exploitation, observed activity included deployment of JSP web shells and reverse shells, privilege escalation, persistent remote-access tooling, and memory-backed execution,” Microsoft wrote. “Threat actors also accessed email and collected authentication and mailbox data, with archive creation and subsequent transfer activity observed.”

The intrusions mixed automated payload delivery with hands-on-keyboard work on compromised mail servers, the company said, and hit organizations in more than one region and industry. “Based on the environments investigated, exploitation was not limited to a single sector or geographic area,” Microsoft said.