Vulnerabilities & Exploits · Ransomware

Interlock Ransomware Uses Zero-Day to Compromise Firewalls

Interlock abused a zero-day in Cisco FMC to run arbitrary Java code as root. AWS saw exploitation from Jan 26, 2026—36 days before Cisco's March 4 disclosure. A misconfigured Interlock server exposed the group's toolkit, indicators, and known victims in healthcare, education, and local government.

9 sources · Mar 20

CVE-2026-20131

NVD KEV

Known exploited · CISA KEV

CVSS 10 CRITICAL: a vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could… Known ransomware campaign use. EPSS 33% (98th percentile).

CISA federal remediation date Mar 22

Timeline

Sources

Vendor digest: Cisco

Part of the PlainSec briefing for 2026-03-24

Every edition of this story: Interlock Ransomware Uses Zero-Day to Compromise Firewalls

More from today