Skip to content
MarketScale
‹ Back to IndustriesSoftware & Technology

CISA flags active SharePoint RCE exploit as Cisco UCM attacks continue

Two critical enterprise vulnerabilities involving SharePoint and Cisco UCM are actively being exploited. These vulnerabilities pose significant risks to collaboration and voice infrastructure, prompting concerns from cybersecurity agencies. Organizations using these systems are urged to take immediate action to mitigate risks.

This story was produced through MarketScale. See how Software & Technology teams put it to work with Executive Thought Leadership.

By MarketScale Newsroom · CisaMicrosoft SharepointCiscoUnified Communications Manager
Share
Learn this in 60 seconds

Key facts, context, and what it means, in one minute.

:60
0:001:00
CISA flags active SharePoint RCE exploit as Cisco UCM attacks continue

Key takeaways

01

Active exploitation of SharePoint and Cisco UCM vulnerabilities detected.

02

Critical risk posed to collaboration and voice infrastructure.

03

Immediate action required from organizations to mitigate risks.

Get featured

Want to get featured in MarketScale Software & Technology?

Create a free MarketScale workspace and get your company's expertise featured across our Software & Technology coverage. No credit card, no demo required.

Request an invite

Two critical vulnerabilities affecting core enterprise infrastructure landed on security teams' radar on July 2, 2026, and both are already being exploited. The U.S. Cybersecurity and Infrastructure Security Agency added a Microsoft SharePoint remote code execution flaw to its Known Exploited Vulnerabilities catalog, while Cisco separately updated its advisory to confirm active attacks against its Unified Communications Manager platform.

SharePoint deserialization flaw draws federal mandate

The SharePoint vulnerability, tracked as CVE-2026-45659, stems from unsafe deserialization of untrusted data. Attackers with low privilege levels can exploit it remotely over the internet to execute arbitrary code on affected servers, with no need for physical access or elevated credentials.

CISA's KEV catalog listing carries real operational weight. Federal civilian agencies face binding patch deadlines once a CVE appears there, and the catalog has historically served as a reliable signal that threat actors are actively scanning for and compromising unpatched instances across both public and private sector networks. Security teams running SharePoint as a document management or intranet backbone should treat this as an active incident until patching is confirmed.

The deserialization attack class is particularly difficult to block with perimeter controls alone. Network scanning engines can identify exposed SharePoint endpoints at scale, meaning the window between a public proof-of-concept and widespread exploitation is now measured in hours, not days.

Cisco UCM: voice infrastructure under active attack

Cisco's updated advisory for CVE-2026-20230 confirms what security researchers had warned about for weeks: the server-side request forgery vulnerability in Unified Communications Manager is no longer just a theoretical risk. Unauthenticated, remote attackers are executing low-complexity requests that create unauthorized files on exposed UCM servers.

Voice infrastructure has historically been treated as lower-risk than data systems, but UCM environments often sit at the intersection of telephony, directory services, and internal application routing. Unauthorized file creation on a UCM server can serve as a foothold for lateral movement or persistent access, making this more than a telephony availability issue.

Financial services organizations are among those aggressively pushing patches this week, according to B2B Tech News, reflecting the sector's sensitivity to communications infrastructure compromise. Organizations in any regulated vertical should assess their UCM exposure and check whether internet-facing or DMZ-adjacent deployments are running affected firmware versions.

A third threat vector: macOS credential harvesting

Separate reporting from July 2 identified a new macOS infostealer that adds a validation step before exfiltrating credentials. Rather than immediately sending stolen data to a command-and-control server, the malware uses AppleScript prompts to locally verify that captured passwords actually work before transmitting them. The approach reduces the malware's network footprint and increases the quality of harvested credentials.

Distributed through malicious ads and deceptive software installers, the threat targets macOS Keychain data. For enterprises that have expanded Mac deployments across developer, finance, or executive teams, this is a concrete reminder that endpoint detection and identity monitoring on macOS requires the same rigor applied to Windows environments.

What this means for your team

  • Audit all SharePoint Server deployments for CVE-2026-45659 patch status immediately; if patches cannot be applied within your change window, consider taking internet-exposed instances offline until they are applied.
  • Inventory Cisco UCM firmware versions across all sites and prioritize patching for any UCM nodes reachable from low-trust or internet-adjacent network segments; review server file system logs for signs of unauthorized file creation.
  • Extend macOS endpoint monitoring to include behavioral detection for unusual AppleScript execution and Keychain access patterns, particularly on devices used by privileged users or those with access to financial or identity systems.
  • Cross-check your patch cadence against CISA's KEV catalog as a standing practice: KEV additions indicate confirmed in-the-wild exploitation and should trigger an immediate response, not a scheduled maintenance window.

Featured companies

Your experts belong here

Every story in MarketScale Software & Technology starts with a company putting its solutions engineers, product teams, and customer engineers on the record. Buyers are already reading this topic. The only question is whose experts they find.

Buyers ask AI engines who to consider, and published expert answers are what those engines cite.

Get your team featuredSee how it works15 minutes, straight to a calendar.

About the author

MarketScale Newsroom
MarketScale NewsroomEditorial Team, MarketScale

The MarketScale Newsroom reports on the companies, technologies, and trends shaping 16 B2B industries. It turns primary sources and expert commentary into clear, useful coverage for the people doing the work.

Follow Software & Technology Insights

Get new expert content in your inbox.

Software & Technology: are you visible to AI?

Before they reach out, Software & Technology buyers ask AI engines which vendors to trust. See how AI describes your company today, and where competitors show up instead.

Free workspace

You just read one Software & Technology expert. Your company is full of them.

This article was produced through MarketScale. The same platform turns your solutions engineers, product teams, and customer engineers into the articles, video, and social content Software & Technology buyers are searching for. Create a free workspace and see it with your own people. No credit card, no demo required.

NPS +73 · 1,000+ creators · 38+ countries

What you get, free

Your own MarketScale Studio workspace
One video edit a month, on us
AI writing, editing, and publishing tools
In-platform coaching to learn the system

More Software & Technology Insights

Airwallex’s $320 million Series H pushes fintech buying teams to price “autonomous finance” into payables and treasury RFPs

Airwallex’s $320 million Series H pushes fintech buying teams to price “autonomous finance” into payables and treasury RFPs

Airwallex has secured $320 million in Series H funding to enhance its agentic bookkeeping and wallet checkout solutions. This investment will prompt finance and IT teams to rethink payment stacks for better control. The focus on 'autonomous finance' suggests a shift towards more integrated financial operations.

  • 01Airwallex raised $320 million in Series H funding.
  • 02Finance and IT teams are encouraged to integrate clearer controls in payment stacks.
  • 03The concept of 'autonomous finance' is driving changes in financial operations.

Aug 21, 2026

Financial services will outspend most U.S. industries in 2026, and H1 B2B tech buying shows where the contracts are moving

Financial services will outspend most U.S. industries in 2026, and H1 B2B tech buying shows where the contracts are moving

The U.S. financial services industry is projected to have a tech budget of $495 billion by 2026. Recent tracking of B2B purchases indicates an acceleration in technology adoption in areas such as security and AI foundations. The financial sector is expected to outspend most other U.S. industries on technology.

  • 01U.S. financial services tech budgets are forecasted to reach $495 billion in 2026.
  • 02B2B purchases in H1 show rapid cycles in security and AI foundations.
  • 03The financial sector is set to outspend most U.S. industries on technology by 2026.

Aug 20, 2026

Etched’s $21 billion valuation forces AI inference buyers to treat racks as contracts, not chips

Etched’s $21 billion valuation forces AI inference buyers to treat racks as contracts, not chips

With a $21 billion valuation, Etched is prompting a shift in how AI inference buyers approach procurement, focusing on racks rather than individual chips. Etched's significant valuation, fueled by a $700 million funding round, underscores the evolving economics of AI inference. This approach emphasizes the importance for enterprises to consider racks as long-term infrastructure investments.

  • 01Etched's $700 million funding round has propelled its valuation to $21 billion.
  • 02AI inference buyers should treat racks as enduring contracts, not just individual components.
  • 03The economics of AI inference are evolving, necessitating changes in procurement strategies.

Aug 19, 2026

Explore More Software & Technology Insights

Read more expert perspectives from across Software & Technology.

Browse Software & Technology Hub

About the Expert

MarketScale Newsroom
MarketScale Newsroom

Editorial Team

MarketScale

The MarketScale Newsroom reports on the companies, technologies, and trends shaping 16 B2B industries. It turns primary sources and expert commentary into clear, useful coverage for the people doing the work.

For B2B teams

Your experts could be publishing here

Stories like this one run on content MarketScale captures from real practitioners. See how your team's expertise becomes coverage in Software & Technology and beyond.

Book a 15-minute demo

Or call us. No forms required. We pick up. 214-945-2512