Vulnerabilità · 193 giorni fa

Interlock Ransomware Exploits Cisco FMC Zero-Day for Root Access

Interlock exploited a zero-day in Cisco Secure Firewall Management Center (CVE-2026-20131) to execute arbitrary Java code as root. AWS threat intelligence observed exploitation beginning Jan 26, 2026, 36 days before Cisco’s March 4 disclosure. A misconfigured Interlock server exposed the group’s multi-stage toolkit and indicators.

CVE-2026-20131

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 10 CRITICAL: a vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could… Impiego noto in campagne ransomware. EPSS 43% (99º percentile).

Data di correzione federale CISA 22 mar

Cronologia

Fonti

9 fonti che coprono questa storia

Entità

Riepilogo fornitore: Cisco

Part of the PlainSec briefing for 2026-03-25

Editions

Storie correlate