Interlock Ransomware Uses Zero-Day to Compromise Firewalls
Interlock ransomware exploited a Cisco Secure Firewall Management Center zero-day (CVE-2026-20131) to execute arbitrary Java code as root on internet-facing FMC devices. Amazon/AWS threat intelligence observed exploitation beginning Jan 26, 2026—36 days before Cisco's March 4 disclosure—granting attackers extended early access to enterprise networks.
CVSS 10 CRITICAL: a vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could… Known ransomware campaign use. EPSS 33% (98th percentile).
Interlock ransomware gang exploited Cisco firewall zero-day weeks before disclosure: Amazon
The Interlock ransomware gang recently exploited a zero-day vulnerability in a popular line of Cisco firewalls before the bug was disclosed publicly, according to an Amazon report.