Volume 1 | July 2026
Welcome to the inaugural edition of the Bullet Consulting Cybersecurity Dispatch. True to our mission, we bring you enterprise-grade threat intelligence with a GLOBAL reach | LOCAL focus. We monitor the latest advisories from the Cybersecurity and Infrastructure Security Agency (CISA) so you can stay ahead of emerging threats and keep your technical infrastructure resilient.
Here are the most critical CISA alerts and vulnerability updates from the past few weeks that require your immediate attention:
On July 1, 2026, CISA added a critical remote code execution (RCE) vulnerability in Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog.
Vulnerability: CVE-2026-45659 (CVSS 8.8) – Deserialization of Untrusted Data
The Threat: An authenticated attacker with just “Site Member” permissions can execute arbitrary code over a network without needing administrative privileges.
Action Required: If you utilize SharePoint Server Subscription Edition, SharePoint Server 2019, or SharePoint Server/Enterprise 2016, apply Microsoft’s out-of-band security updates immediately. CISA mandated federal agencies to patch this within three days, underscoring its severity.
In late June, CISA added two other actively exploited vulnerabilities that pose significant risks to enterprise environments:
Cisco Unified Communications Manager (CVE-2026-20230): A Server-Side Request Forgery (SSRF) vulnerability being actively exploited in the wild.
PTC Windchill and FlexPLM (CVE-2026-12569): An improper input validation flaw granting an attack vector into product lifecycle management systems.
Action Required: Review your infrastructure for these systems. Ensure all edge and internal communications appliances are running the latest patched firmware.
CISA issued an alert on June 18, 2026, urging administrators to lock down Fortinet devices following widespread reports of credential exposure. Unpatched or misconfigured VPNs and firewalls are prime targets for initial access brokers.
Action Required: Audit your Fortinet configurations, enforce strict multi-factor authentication (MFA) across all administrative and user VPN portals, and rotate any potentially exposed credentials.
While we handle the infrastructure, your team is the first line of defense. Share these everyday habits with your staff to drastically reduce your organizational risk:
The 3-Second Pause: Phishing emails rely on urgency. If an email demands immediate action (e.g., “Invoice Overdue,” “Password Expiring”), take three seconds to check the actual sender address, not just the display name.
Beware of MFA Fatigue: If you receive a Multi-Factor Authentication (MFA) prompt on your phone that you did not initiate, do not approve it. Attackers often spam these prompts hoping you’ll hit “Approve” just to make it stop.
Passphrases Beat Passwords: Instead of a complex, hard-to-remember password like P@ssw0rd1!, use a passphrase made of four random words (e.g., HorseBatteryStapleCoffee). They are mathematically harder to crack and much easier to remember.
Don’t Ignore the Reboot: When your computer or phone asks to restart to install updates, do it by the end of the day. Those updates often contain patches for the exact vulnerabilities attackers are actively exploiting.
Is Your Infrastructure Secure? Vulnerability management can’t just be a checklist — it needs to be a continuous, risk-based strategy. If you need assistance auditing your environment for these CVEs, hardening your edge devices, or securing your SharePoint architecture, Bullet Consulting is here to help.
Bullet Consulting
Uncompromising Cybersecurity. Resilient Infrastructure.