U.S. CISA adds a flaw in Cisco FMC and Cisco SCC Firewall Management to its Known Exploited Vulnerabilities catalog
ID: 73017f7b-6b7a-5f30-9df0-fe4428e58d11
STIX ID: report--73017f7b-6b7a-5f30-9df0-fe4428e58d11
Feed Name: Security Affairs
Threat Score
CISA added CVE-2026-20131 (CVSS 10.0), a remote unauthenticated Java deserialization flaw in Cisco Secure FMC and SCC web management interfaces, to its Known Exploited Vulnerabilities catalog after evidence showed the Interlock ransomware group actively exploited the zero-day starting 26 January 2026; Cisco released fixes in early March and CISA ordered federal remediation by March 22, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
