Vulnerabilities & Exploits · Ransomware
Interlock Ransomware Uses Zero-Day to Compromise Firewalls Interlock abused a zero-day in Cisco FMC to run arbitrary Java code as root. AWS saw exploitation from Jan 26, 2026—36 days before Cisco's March 4 disclosure. A misconfigured Interlock server exposed the group's toolkit, indicators, and known victims in healthcare, education, and local government.
9 sources · Mar 20
NVD KEV
Known exploited · CISA KEV
CVSS 10 CRITICAL: a vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could… Known ransomware campaign use. EPSS 33% (98th percentile).
CISA federal remediation date Mar 22
Timeline Sources Mar 20 Help Net Security
Cisco FMC flaw was exploited by Interlock weeks before patch (CVE-2026-20131) - Help Net Security
A Cisco Secure FMC flaw (CVE-2026-20131) patched in early March 2026 has been exploited as a zero-day by the Interlock ransomware gang.
original Mar 20 Dark Reading
Interlock Ransomware Targets Cisco Enterprise Firewalls
The ransomware gang, known for double-extortion attacks, had access to a critical Cisco firewall vulnerability weeks before it was publicly disclosed.
original Mar 19 The Record from Recorded Future
Interlock ransomware gang exploited Cisco firewall zero-day weeks before disclosure: Amazon
The Interlock ransomware gang recently exploited a zero-day vulnerability in a popular line of Cisco firewalls before the bug was disclosed publicly, according to an Amazon report.
original Vendor digest: Cisco
Part of the PlainSec briefing for 2026-03-24
Every edition of this story: Interlock Ransomware Uses Zero-Day to Compromise Firewalls
More from today
Vulnerabilities & Exploits · Ransomware
Interlock Ransomware Uses Zero-Day to Compromise Firewalls Interlock abused a zero-day in Cisco FMC to run arbitrary Java code as root. AWS saw exploitation from Jan 26, 2026—36 days before Cisco's March 4 disclosure. A misconfigured Interlock server exposed the group's toolkit, indicators, and known victims in healthcare, education, and local government.
9 sources · Mar 20
NVD KEV
Known exploited · CISA KEV
CVSS 10 CRITICAL: a vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could… Known ransomware campaign use. EPSS 33% (98th percentile).
CISA federal remediation date Mar 22
Timeline Sources Mar 20 Help Net Security
Cisco FMC flaw was exploited by Interlock weeks before patch (CVE-2026-20131) - Help Net Security
A Cisco Secure FMC flaw (CVE-2026-20131) patched in early March 2026 has been exploited as a zero-day by the Interlock ransomware gang.
original Mar 20 Dark Reading
Interlock Ransomware Targets Cisco Enterprise Firewalls
The ransomware gang, known for double-extortion attacks, had access to a critical Cisco firewall vulnerability weeks before it was publicly disclosed.
original Mar 19 The Record from Recorded Future
Interlock ransomware gang exploited Cisco firewall zero-day weeks before disclosure: Amazon
The Interlock ransomware gang recently exploited a zero-day vulnerability in a popular line of Cisco firewalls before the bug was disclosed publicly, according to an Amazon report.
original Vendor digest: Cisco
Part of the PlainSec briefing for 2026-03-24
Every edition of this story: Interlock Ransomware Uses Zero-Day to Compromise Firewalls
More from today