SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefWednesday, September 16, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Cisco Secure Email Gateway CVE-2026-76461 Actively Exploited | CRITICAL |
|
5 C2 IPs | 80 OTX IOCs | 39 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is dominated by active exploitation of critical infrastructure, highlighted by a root command execution vulnerability in Cisco Secure Email Gateway (CVE-2026-76461) and ransomware groups targeting VMware vCenter. Additionally, web-facing environments face severe risk from backdoored WordPress plugins (Admin Menu Editor Pro and WooCommerce Wholesale Lead Capture) and Linux privilege escalation vulnerabilities in Acronis backup plugins and LiteSpeed Web Server Enterprise. |
|
■ CRITICAL STORIES Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution A critical vulnerability (CVE-2026-76461) in AsyncOS Software for Cisco Secure Email Gateway allows unauthenticated remote attackers to execute commands with root privileges, posing an immediate threat to enterprise email security. |
CISA: Critical VMware RCE flaw now exploited by ransomware gangs Ransomware operators have joined ongoing exploitation of a critical VMware vCenter Remote Code Execution (RCE) vulnerability, making immediate patching a top priority for virtualization administrators. |
Acronis warns of actively exploited flaw in its cPanel backup plugin A high-severity local privilege escalation vulnerability in the Acronis backup plugin for cPanel, WHM, and Plesk is being actively exploited in the wild to compromise Linux servers. |
Malicious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites Threat actors compromised a plugin developer's site to distribute backdoored updates of Admin Menu Editor Pro, automatically establishing hidden administrator accounts on over 1,500 websites. |
|
■ CVEs IDENTIFIED CVE-2026-76461 Cisco Secure Email Gateway (AsyncOS) — Root Command Execution |
[CVE-TBD] VMware vCenter Server — Remote Code Execution (RCE) exploited by ransomware |
[CVE-TBD] Acronis Backup Plugin for cPanel/WHM/Plesk — Linux Local Privilege Escalation (LPE) |
[CVE-TBD] Admin Menu Editor Pro Plugin — Backdoor via unauthorized admin account creation |
|
■ THREAT ACTORS REF9334 (KREMLIN) | Cybercrime / Banking Malware Group |
Deploying KREMLIN toolkit to hijack Chrome and Edge browsers for credential and session token theft. |
Iranian Cyber Spies | State-Sponsored / APT |
Using Telegram-controlled malware and fake MRI scan lures to spy on dissidents, journalists, and activists. |
Black Axe | Cybercrime Syndicate |
Five alleged leaders extradited to the US to face wire fraud and money laundering charges. |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | Active exploitation of Cisco Secure Email Gateway (CVE-2026-76461) and VMware vCenter. |
| T1068 | | Exploitation for Privilege Escalation | Exploited in Acronis cPanel backup plugin and LiteSpeed Web Server Enterprise. |
| T1505.003 | | Web Shell | PHP backdoors uploaded via WooCommerce Wholesale Lead Capture plugin. |
| T1098 | | Account Manipulation | Creation of hidden admin accounts via malicious Admin Menu Editor Pro plugin. |
| T1185 | | Browser Session Hijacking | KREMLIN malware hijacking Chrome and Edge to steal session tokens. |
| T1102 | | Web Service | Iranian actors using Telegram to control Windows malware. |
|
■ PATCH PRIORITY Cisco Secure Email Gateway — CVE-2026-76461 actively exploited in the wild for root command execution — [THN] |
VMware vCenter Server — Critical RCE vulnerability targeted by ransomware gangs — [BC] |
Acronis Backup Plugin for cPanel/WHM/Plesk — Active exploitation of Linux local privilege escalation — [BC] |
LiteSpeed Web Server Enterprise — Critical vulnerability allowing low-privilege users to gain root access — [THN] |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Patch Cisco Secure Email Gateway immediately to address CVE-2026-76461 to prevent root command execution. |
| 2 | [P1] Apply the security patch for VMware vCenter Server to mitigate the critical RCE vulnerability actively targeted by ransomware. |
| 3 | [P1] Update the Acronis backup plugin for cPanel, WHM, and Plesk to the latest secure version to block active local privilege escalation exploits. |
| 4 | [P2] Audit all WordPress installations for the Admin Menu Editor Pro and WooCommerce Wholesale Lead Capture plugins; remove unauthorized admin accounts and web shells. |
| 5 | [P2] Secure Vite development servers by ensuring they are not exposed to the public internet and audit cloud credentials for potential exposure. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |