Vulnerabilities & Exploits · Ransomware
Interlock Compromises Enterprise Firewalls via Cisco FMC Zero-Day Amazon/AWS threat intelligence observed exploitation beginning January 26, 2026 — 36 days before Cisco publicly disclosed the vulnerability. A misconfigured Interlock staging server exposed the group's multi-stage toolkit and indicators of compromise.
9 sources · Mar 20
NVD KEV
Known exploited · CISA KEV
CVSS 10 CRITICAL: a vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could… Known ransomware campaign use. EPSS 33% (98th percentile).
CISA federal remediation date Mar 22
Timeline Sources Mar 20 Dark Reading
Interlock Ransomware Targets Cisco Enterprise Firewalls
The ransomware gang, known for double-extortion attacks, had access to a critical Cisco firewall vulnerability weeks before it was publicly disclosed.
original Mar 20 Help Net Security
Cisco FMC flaw was exploited by Interlock weeks before patch (CVE-2026-20131) - Help Net Security
A Cisco Secure FMC flaw (CVE-2026-20131) patched in early March 2026 has been exploited as a zero-day by the Interlock ransomware gang.
original Mar 19 The Record from Recorded Future
Interlock ransomware gang exploited Cisco firewall zero-day weeks before disclosure: Amazon
The Interlock ransomware gang recently exploited a zero-day vulnerability in a popular line of Cisco firewalls before the bug was disclosed publicly, according to an Amazon report.
original Vendor digest: Cisco
Part of the PlainSec briefing for 2026-03-19
Every edition of this story: Interlock Compromises Enterprise Firewalls via Cisco FMC Zero-Day
More from today
Vulnerabilities & Exploits · Ransomware
Interlock Compromises Enterprise Firewalls via Cisco FMC Zero-Day Amazon/AWS threat intelligence observed exploitation beginning January 26, 2026 — 36 days before Cisco publicly disclosed the vulnerability. A misconfigured Interlock staging server exposed the group's multi-stage toolkit and indicators of compromise.
9 sources · Mar 20
NVD KEV
Known exploited · CISA KEV
CVSS 10 CRITICAL: a vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could… Known ransomware campaign use. EPSS 33% (98th percentile).
CISA federal remediation date Mar 22
Timeline Sources Mar 20 Dark Reading
Interlock Ransomware Targets Cisco Enterprise Firewalls
The ransomware gang, known for double-extortion attacks, had access to a critical Cisco firewall vulnerability weeks before it was publicly disclosed.
original Mar 20 Help Net Security
Cisco FMC flaw was exploited by Interlock weeks before patch (CVE-2026-20131) - Help Net Security
A Cisco Secure FMC flaw (CVE-2026-20131) patched in early March 2026 has been exploited as a zero-day by the Interlock ransomware gang.
original Mar 19 The Record from Recorded Future
Interlock ransomware gang exploited Cisco firewall zero-day weeks before disclosure: Amazon
The Interlock ransomware gang recently exploited a zero-day vulnerability in a popular line of Cisco firewalls before the bug was disclosed publicly, according to an Amazon report.
original Vendor digest: Cisco
Part of the PlainSec briefing for 2026-03-19
Every edition of this story: Interlock Compromises Enterprise Firewalls via Cisco FMC Zero-Day
More from today