Microsoft warned that attackers are exploiting a critical Zimbra Collaboration Suite vulnerability (CVE-2026-73570) to steal emails and authentication credentials from organizations. The flaw allows unauthenticated remote command execution, and Synacor delayed disclosure for over three weeks after releasing a patch on July 20. Shadowserver Foundation found approximately 10,000 compromised instances, with threat actors deploying web shells, reverse shells, and conducting hands-on attacks across multiple sectors and regions.