Interlock Ransomware Exploits Cisco FMC Zero-Day CVE-2026-20131 for Root Access
A recent serious security vulnerability in Cisco Secure Firewall Management Center (FMC) software is being exploited by an active Interlock ransomware operation, according to Amazon Threat Intelligence.
The vulnerability in question is CVE-2026-20131 (CVSS score: 10.0), a case of insecure deserialization of user-supplied Java byte stream that could enable a remote, unauthenticated attacker to get around authentication and run arbitrary Java code as root on a compromised device.
Data obtained from the tech giant's MadPot global sensor network indicates that the security hole had been exploited as a zero-day since January 26, 2026—more than a month before Cisco made it public.
Interlock had a zero-day in their possession, which gave them a week's notice to compromise businesses bef...

