logo

Cisco Firewall 0-day Vulnerability Exploited in the Wild to Deploy Interlock Ransomware

ID: 27b37c27-af23-5ba7-bbbd-157b55cf224f

STIX ID: report--27b37c27-af23-5ba7-bbbd-157b55cf224f

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-03-18

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Amazon threat intelligence discovered the Interlock ransomware group exploiting a critical Cisco Secure Firewall Management Center zero-day (CVE-2026-20131) in the wild beginning 26 January 2026—36 days prior to the public disclosure—enabling unauthenticated Java code execution as root. The exposed infrastructure revealed a tailored toolkit for each target including a Linux ELF ransom binary, PowerShell host enumeration and zipping, Java/JavaScript remote access trojans, a memory-resident Java webshell, and Linux reverse-proxy scripts; Interlock targets critical sectors and uses double-extortion tactics, so organizations should apply Cisco patches immediately and prioritize behavioral/memory-based detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.