logo

CISA orders feds to patch max-severity Cisco flaw by Sunday

ID: c07af924-cd14-5755-b051-3a3da28ba6ca

STIX ID: report--c07af924-cd14-5755-b051-3a3da28ba6ca

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-03-20

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

CISA ordered federal agencies to urgently patch CVE-2026-20131 in Cisco Secure Firewall Management Center — a maximum-severity insecure-deserialization flaw allowing unauthenticated remote Java code execution as root — after Cisco confirmed no workaround and updated the advisory to report active exploitation. Amazon intelligence and vendor updates link the Interlock ransomware group to exploitation of this zero-day since January, and CISA added the CVE to its Known Exploited Vulnerabilities catalog and set an immediate remediation deadline for affected federal systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.