Cisco Email Gateway Under Attack, Two WordPress Flaws Exploited, and VMware Ransomware Alert

by The Creator | Sep 15, 2026

Ransomware attack response requires immediate action this week. CISA warned that gangs are actively exploiting unpatched VMware vCenter servers, Cisco email gateways, and WordPress plugins to breach small businesses and deploy encryption attacks.

CISA has warned that attackers are actively exploiting a critical zero-day vulnerability (CVE-2026-76461) in Cisco Secure Email Gateway appliances. The SQL injection flaw could allow attackers to gain full control of email systems. Cisco has released patches, and businesses using these appliances should update immediately.

Two critical WordPress vulnerabilities are under active exploitation. The WooCommerce Wholesale Lead Capture plugin (CVE-2026-27540, CVSS 9.8) allows unauthenticated attackers to upload PHP backdoors and take over sites without credentials. Additionally, The Events Calendar plugin, installed on over 600,000 sites, patched two critical vulnerability chains in version 6.17.4.1 that could allow remote code execution and full site compromise. Both plugins have updates available.

CISA also issued an alert that ransomware gangs are now exploiting a critical VMware vCenter RCE vulnerability that was patched in July. Organizations that delayed the summer update are now targeted by ransomware operators.

A critical vulnerability in cPanel's LiteSpeed Web Server Enterprise (affecting versions before 6.3.7) allows any low-privileged shared-hosting user to escalate privileges to root level, potentially compromising all websites on the server. Hosting providers should upgrade immediately.

In social engineering news, HBO Max's verified Reddit account was hijacked to distribute 108 malicious ads spreading information-stealing malware. A cryptocurrency wallet lost $7.8 million due to a simple coding error. Five alleged leaders of the Black Axe cybercrime syndicate were extradited to the U.S. to face wire fraud and money laundering charges related to global financial fraud operations.

Which ransomware attack threats target your business this week?

Four critical vulnerabilities are being exploited right now against small business systems. VMware vCenter (CVE-2026-76461) affects organizations that skipped July patches. Cisco Secure Email Gateway (SQL injection) gives attackers full email control. WordPress sites running WooCommerce Wholesale Lead Capture or Events Calendar plugins face remote code execution and backdoor installation on over 600,000 sites. cPanel servers with LiteSpeed Web Server versions before 6.3.7 allow any hosting account user to escalate to root access, compromising all customer sites. Action: patch all four systems today, prioritize email and backup infrastructure, and verify your incident response plan includes offline backup recovery and CISA notification protocols.

Key takeaways

  • VMware vCenter ransomware targeting continues. Patch to latest version immediately if you delayed July updates.
  • Cisco email gateway SQL injection is live threat. Update appliances within 24 hours to block attacker access.
  • WordPress plugins WooCommerce and Events Calendar have active exploits. Update to patched versions before malware backdoors your site.
  • cPanel hosting providers must upgrade LiteSpeed before 6.3.7 to prevent privilege escalation affecting all hosted sites.

Frequently asked questions

What should I do right now if I use Cisco email gateway or VMware vCenter?

Patch both systems today. For Cisco, apply the SQL injection fix immediately to prevent email compromise. For VMware, update to the latest vCenter version if you missed July patches. Test patches in a non-production environment first if possible, but do not delay deployment given active exploitation.

How do I know if my WordPress site is vulnerable?

Check your installed plugins in the WordPress admin dashboard. Look for WooCommerce Wholesale Lead Capture and The Events Calendar. If installed, update both to the latest versions now. Remove any plugins you no longer use to reduce attack surface.

What happens if ransomware encrypts my files before I patch?

Recovery depends on offline backups. Do not pay ransom. Contact law enforcement and CISA immediately. Restore from backups that were disconnected from your network before the attack. This is why offline backup strategy matters more than patches alone.

Which threat should I address first?

Email systems first, then web applications, then hosting infrastructure. Email compromise gives attackers immediate access to credentials and internal communication. Web and hosting attacks follow once email is secured.

Sources

Keep reading