Skip to content
MarketScale
‹ Back to IndustriesSoftware & Technology

CISA flags active SharePoint RCE exploit as Cisco UCM attacks continue

Two critical enterprise vulnerabilities involving SharePoint and Cisco UCM are actively being exploited. These vulnerabilities pose significant risks to collaboration and voice infrastructure, prompting concerns from cybersecurity agencies. Organizations using these systems are urged to take immediate action to mitigate risks.

This story was produced through MarketScale. See how Software & Technology teams put it to work with Executive Thought Leadership.

By MarketScale Newsroom · CisaMicrosoft SharepointCiscoUnified Communications Manager
Share
Learn this in 60 seconds

Key facts, context, and what it means, in one minute.

:60
0:001:00
CISA flags active SharePoint RCE exploit as Cisco UCM attacks continue

Key takeaways

01

Active exploitation of SharePoint and Cisco UCM vulnerabilities detected.

02

Critical risk posed to collaboration and voice infrastructure.

03

Immediate action required from organizations to mitigate risks.

Two critical vulnerabilities affecting core enterprise infrastructure landed on security teams' radar on July 2, 2026, and both are already being exploited. The U.S. Cybersecurity and Infrastructure Security Agency added a Microsoft SharePoint remote code execution flaw to its Known Exploited Vulnerabilities catalog, while Cisco separately updated its advisory to confirm active attacks against its Unified Communications Manager platform.

SharePoint deserialization flaw draws federal mandate

The SharePoint vulnerability, tracked as CVE-2026-45659, stems from unsafe deserialization of untrusted data. Attackers with low privilege levels can exploit it remotely over the internet to execute arbitrary code on affected servers, with no need for physical access or elevated credentials.

CISA's KEV catalog listing carries real operational weight. Federal civilian agencies face binding patch deadlines once a CVE appears there, and the catalog has historically served as a reliable signal that threat actors are actively scanning for and compromising unpatched instances across both public and private sector networks. Security teams running SharePoint as a document management or intranet backbone should treat this as an active incident until patching is confirmed.

The deserialization attack class is particularly difficult to block with perimeter controls alone. Network scanning engines can identify exposed SharePoint endpoints at scale, meaning the window between a public proof-of-concept and widespread exploitation is now measured in hours, not days.

Cisco UCM: voice infrastructure under active attack

Cisco's updated advisory for CVE-2026-20230 confirms what security researchers had warned about for weeks: the server-side request forgery vulnerability in Unified Communications Manager is no longer just a theoretical risk. Unauthenticated, remote attackers are executing low-complexity requests that create unauthorized files on exposed UCM servers.

Voice infrastructure has historically been treated as lower-risk than data systems, but UCM environments often sit at the intersection of telephony, directory services, and internal application routing. Unauthorized file creation on a UCM server can serve as a foothold for lateral movement or persistent access, making this more than a telephony availability issue.

Financial services organizations are among those aggressively pushing patches this week, according to B2B Tech News, reflecting the sector's sensitivity to communications infrastructure compromise. Organizations in any regulated vertical should assess their UCM exposure and check whether internet-facing or DMZ-adjacent deployments are running affected firmware versions.

A third threat vector: macOS credential harvesting

Separate reporting from July 2 identified a new macOS infostealer that adds a validation step before exfiltrating credentials. Rather than immediately sending stolen data to a command-and-control server, the malware uses AppleScript prompts to locally verify that captured passwords actually work before transmitting them. The approach reduces the malware's network footprint and increases the quality of harvested credentials.

Distributed through malicious ads and deceptive software installers, the threat targets macOS Keychain data. For enterprises that have expanded Mac deployments across developer, finance, or executive teams, this is a concrete reminder that endpoint detection and identity monitoring on macOS requires the same rigor applied to Windows environments.

What this means for your team

  • Audit all SharePoint Server deployments for CVE-2026-45659 patch status immediately; if patches cannot be applied within your change window, consider taking internet-exposed instances offline until they are applied.
  • Inventory Cisco UCM firmware versions across all sites and prioritize patching for any UCM nodes reachable from low-trust or internet-adjacent network segments; review server file system logs for signs of unauthorized file creation.
  • Extend macOS endpoint monitoring to include behavioral detection for unusual AppleScript execution and Keychain access patterns, particularly on devices used by privileged users or those with access to financial or identity systems.
  • Cross-check your patch cadence against CISA's KEV catalog as a standing practice: KEV additions indicate confirmed in-the-wild exploitation and should trigger an immediate response, not a scheduled maintenance window.

Featured companies

About the author

MarketScale Newsroom
MarketScale NewsroomEditorial Team, MarketScale

The MarketScale Newsroom reports on the companies, technologies, and trends shaping 16 B2B industries. It turns primary sources and expert commentary into clear, useful coverage for the people doing the work.

Software & Technology: are you visible to AI?

Before they reach out, Software & Technology buyers ask AI engines which vendors to trust. See how AI describes your company today, and where competitors show up instead.

Free workspace

You just read one expert. Imagine publishing your whole team.

This article was produced through MarketScale. Create a free workspace and turn your own team's expertise into articles, video, and social posts. No credit card, no demo required.

NPS +73 · 1,000+ creators · 38+ countries

What you get, free

Your own MarketScale Studio workspace
One video edit a month, on us
AI writing, editing, and publishing tools
In-platform coaching to learn the system

More Software & Technology Insights

OpenAI, Anthropic, and Google are competing for startups with credit packages topping $3M

OpenAI, Anthropic, and Google are competing for startups with credit packages topping $3M

AI model developers like OpenAI, Anthropic, and Google are offering early-stage startups computing credits and discounts worth over $3 million. These incentives are changing how startups assess the risk of vendor lock-in. Companies are using these offers to appeal to emerging enterprises and expand their influence in the AI industry.

  • 01AI companies are offering startups over $3 million in computing credits and discounts.
  • 02These offers influence how startups consider vendor lock-in risks.
  • 03OpenAI, Anthropic, and Google are the major players in this initiative.

Jul 9, 2026

Microsoft launches $2.5B AI implementation subsidiary with 6,000 embedded engineers

Microsoft launches $2.5B AI implementation subsidiary with 6,000 embedded engineers

Microsoft has launched a new subsidiary called Microsoft Frontier Co., investing $2.5 billion to embed 6,000 engineers directly with enterprise clients. This move is in line with similar strategies by AWS, Anthropic, and OpenAI. The initiative aims to bolster AI capabilities by having engineers work closely within client operations.

  • 01Microsoft launches a $2.5 billion AI implementation subsidiary.
  • 026,000 engineers are deployed directly into enterprise clients.
  • 03Similar strategies have been seen from AWS, Anthropic, and OpenAI.

Jul 9, 2026

Anthropic, Microsoft, and Gartner signal a billing model reckoning for enterprise SaaS buyers

Anthropic, Microsoft, and Gartner signal a billing model reckoning for enterprise SaaS buyers

Usage-based billing is becoming more prevalent in AI SaaS platforms, with key players like Anthropic, Microsoft, and Oracle adopting this approach simultaneously. This shift indicates a significant change for enterprise SaaS buyers in terms of billing models. The trend highlights the importance for enterprises to adapt and understand this model for effective budget management.

  • 01Usage-based billing is expanding in AI SaaS platforms.
  • 02Anthropic, Microsoft, and Oracle are moving towards this billing model.
  • 03Enterprise buyers need to adapt to changing billing approaches.

Jul 9, 2026

Explore More Software & Technology Insights

Read more expert perspectives from across Software & Technology.

Browse Software & Technology Hub

About the Expert

MarketScale Newsroom
MarketScale Newsroom

Editorial Team

MarketScale

The MarketScale Newsroom reports on the companies, technologies, and trends shaping 16 B2B industries. It turns primary sources and expert commentary into clear, useful coverage for the people doing the work.