logo

Exploited in the Wild: Interlock Ransomware Weaponizes Critical 10.0 CVSS Cisco Zero-Day

ID: 27fd1a19-349e-50ad-bdc4-99cf25d862cb

STIX ID: report--27fd1a19-349e-50ad-bdc4-99cf25d862cb

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-03-19

Date Updated: 2026-04-23

Author: Ddos

...
...

Amazon uncovered an active Interlock ransomware campaign exploiting a critical zero-day (CVE-2026-20131, CVSS 10) in Cisco Secure Firewall Management Center that allows unauthenticated remote root code execution via insecure Java deserialization; the group used the flaw since January, deployed custom Java/JavaScript RATs and a fileless JVM webshell, and operated a staging server that revealed comprehensive tooling for reconnaissance, laundering, and log erasure—organizations using FMC should apply Cisco’s patches immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.