Cisco FMC flaw was exploited by Interlock weeks before patch (CVE-2026-20131)
ID: 726e8f13-412d-5e10-a0f1-a83cb1631e9d
STIX ID: report--726e8f13-412d-5e10-a0f1-a83cb1631e9d
Feed Name: Help Net Security
Threat Score
A critical zero-day (CVE-2026-20131) in Cisco Secure Firewall Management Center—an insecure Java deserialization in the FMC web interface—was actively exploited by the Interlock ransomware gang beginning January 26, 2026, enabling unauthenticated remote code execution and root escalation; Amazon/AWS observed the exploitation, recovered attacker tooling and malware, and published IOCs while Cisco and CISA issued advisories and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
