Daily Security Intel

Archives
Log in
Subscribe
September 16, 2026

[SecurityIntel] 16 Sep | Cisco Secure Email Gateway CVE-2026-76461 Actively Exploited

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Wednesday, September 16, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Cisco Secure Email Gateway CVE-2026-76461 Actively Exploited

CRITICAL

5

C2 IPs

80

OTX IOCs

39

ARTICLES

■ ANALYST TLDR

Today's threat landscape is dominated by active exploitation of critical infrastructure, highlighted by a root command execution vulnerability in Cisco Secure Email Gateway (CVE-2026-76461) and ransomware groups targeting VMware vCenter. Additionally, web-facing environments face severe risk from backdoored WordPress plugins (Admin Menu Editor Pro and WooCommerce Wholesale Lead Capture) and Linux privilege escalation vulnerabilities in Acronis backup plugins and LiteSpeed Web Server Enterprise.

■ CRITICAL STORIES

CRITICAL#1

Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

A critical vulnerability (CVE-2026-76461) in AsyncOS Software for Cisco Secure Email Gateway allows unauthenticated remote attackers to execute commands with root privileges, posing an immediate threat to enterprise email security.

CRITICAL#2

CISA: Critical VMware RCE flaw now exploited by ransomware gangs

Ransomware operators have joined ongoing exploitation of a critical VMware vCenter Remote Code Execution (RCE) vulnerability, making immediate patching a top priority for virtualization administrators.

HIGH#3

Acronis warns of actively exploited flaw in its cPanel backup plugin

A high-severity local privilege escalation vulnerability in the Acronis backup plugin for cPanel, WHM, and Plesk is being actively exploited in the wild to compromise Linux servers.

HIGH#4

Malicious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Threat actors compromised a plugin developer's site to distribute backdoored updates of Admin Menu Editor Pro, automatically establishing hidden administrator accounts on over 1,500 websites.

■ CVEs IDENTIFIED

CVE-2026-76461

Cisco Secure Email Gateway (AsyncOS) — Root Command Execution

Critical (9.8)

[CVE-TBD]

VMware vCenter Server — Remote Code Execution (RCE) exploited by ransomware

Critical

[CVE-TBD]

Acronis Backup Plugin for cPanel/WHM/Plesk — Linux Local Privilege Escalation (LPE)

High

[CVE-TBD]

Admin Menu Editor Pro Plugin — Backdoor via unauthorized admin account creation

High

■ THREAT ACTORS

REF9334 (KREMLIN)

Cybercrime / Banking Malware Group

Deploying KREMLIN toolkit to hijack Chrome and Edge browsers for credential and session token theft.

Iranian Cyber Spies

State-Sponsored / APT

Using Telegram-controlled malware and fake MRI scan lures to spy on dissidents, journalists, and activists.

Black Axe

Cybercrime Syndicate

Five alleged leaders extradited to the US to face wire fraud and money laundering charges.

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Active exploitation of Cisco Secure Email Gateway (CVE-2026-76461) and VMware vCenter.
T1068
Exploitation for Privilege Escalation | Exploited in Acronis cPanel backup plugin and LiteSpeed Web Server Enterprise.
T1505.003
Web Shell | PHP backdoors uploaded via WooCommerce Wholesale Lead Capture plugin.
T1098
Account Manipulation | Creation of hidden admin accounts via malicious Admin Menu Editor Pro plugin.
T1185
Browser Session Hijacking | KREMLIN malware hijacking Chrome and Edge to steal session tokens.
T1102
Web Service | Iranian actors using Telegram to control Windows malware.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Cisco Secure Email Gateway — CVE-2026-76461 actively exploited in the wild for root command execution — [THN]

[P1 PATCH NOW]≤24h

VMware vCenter Server — Critical RCE vulnerability targeted by ransomware gangs — [BC]

[P1 PATCH NOW]≤24h

Acronis Backup Plugin for cPanel/WHM/Plesk — Active exploitation of Linux local privilege escalation — [BC]

[P2 PATCH NOW]≤72h

LiteSpeed Web Server Enterprise — Critical vulnerability allowing low-privilege users to gain root access — [THN]

■ RECOMMENDED ACTIONS TODAY

1[P1] Patch Cisco Secure Email Gateway immediately to address CVE-2026-76461 to prevent root command execution.
2[P1] Apply the security patch for VMware vCenter Server to mitigate the critical RCE vulnerability actively targeted by ransomware.
3[P1] Update the Acronis backup plugin for cPanel, WHM, and Plesk to the latest secure version to block active local privilege escalation exploits.
4[P2] Audit all WordPress installations for the Admin Menu Editor Pro and WooCommerce Wholesale Lead Capture plugins; remove unauthorized admin accounts and web shells.
5[P2] Secure Vite development servers by ensuring they are not exposed to the public internet and audit cloud credentials for potential exposure.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 17 Sep | First Agentic AI Data Breach Reported in Spain Older → [SecurityIntel] 15 Sep | Red Heron Exploits Gitea RCE Internationally
Powered by Buttondown, the easiest way to start and grow your newsletter.