Interlock Ransomware Exploits Cisco FMC Zero-Day for Root Access
Interlock exploited a zero-day in Cisco Secure Firewall Management Center (CVE-2026-20131) to execute arbitrary Java code as root. AWS threat intelligence observed exploitation beginning Jan 26, 2026, 36 days before Cisco’s March 4 disclosure. A misconfigured Interlock server exposed the group’s multi-stage toolkit and indicators.
CVSS 10 CRITICAL: a vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could… Known ransomware campaign use. EPSS 33% (98th percentile).
The Interlock ransomware gang recently exploited a zero-day vulnerability in a popular line of Cisco firewalls before the bug was disclosed publicly, according to an Amazon report.
Amazon threat intelligence has identified an active Interlock ransomware campaign exploiting CVE-2026-20131, a critical vulnerability in Cisco Secure Firewall Management Center (FMC) Software that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device, which was disclosed by Cisco on March 4, 2026.
The Interlock ransomware gang has been exploiting a maximum severity remote code execution (RCE) vulnerability in Cisco's Secure Firewall Management Center (FMC) software in zero-day attacks since late January.