logo

Interlock group exploiting the CISCO FMC flaw CVE-2026-20131 36 days before disclosure

ID: 588ab761-5a7d-5ef5-be3d-e4265a17b97a

STIX ID: report--588ab761-5a7d-5ef5-be3d-e4265a17b97a

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-03-19

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Amazon and security researchers observed the Interlock ransomware group exploiting a critical Cisco Secure FMC zero-day (CVE-2026-20131, CVSS 10.0) starting January 26, 2026—36 days before public disclosure—allowing unauthenticated Java deserialization leading to root remote code execution. The report details Interlock's multi-stage operations (custom backdoors, ELF malware, PowerShell reconnaissance, fileless webshells, proxy relays), exposed toolkits and IoCs recovered from a misconfigured server, sectors targeted (education, healthcare, industry, government), and urgent patching and detection recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.