Interlock ransomware has been actively exploiting CVE-2026-20131, a critical CVSS 10.0 insecure deserialization flaw in Cisco Secure Firewall Management Center (FMC), to gain unauthenticated remote code execution and run arbitrary Java code as root on vulnerable devices. Amazon Threat Intelligence reported that exploitation began on January 26, 2026, roughly 36 days before Cisco publicly disclosed and patched the issue on March 4, giving the threat actor a meaningful zero-day window against enterprise firewall management infrastructure.
Amazon said its MadPot sensor network and an attacker misconfigured infrastructure server exposed Interlock’s broader operational toolkit, including a multi-stage attack chain, custom remote access trojans, reconnaissance scripts, and evasion methods. Reporting indicates the attacks used crafted HTTP requests against a specific FMC path, followed by outbound confirmation traffic and retrieval of additional ELF binaries from remote infrastructure. Cisco acknowledged Amazon’s findings, updated its advisory, and urged customers to patch immediately, while Amazon said it did not observe AWS infrastructure or customer workloads on AWS being involved in the campaign.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
On March 18, 2026, Amazon threat intelligence reported that Interlock had exploited the Cisco flaw as a zero-day for 36 days before disclosure and attributed the activity to the ransomware group. The report described a multi-stage intrusion chain, including crafted HTTP requests, payload retrieval, custom RATs, reconnaissance tooling, a memory-resident web shell, and ScreenConnect-based persistence, aided by an operational security mistake that exposed Interlock infrastructure.
Cisco publicly disclosed CVE-2026-20131 and released fixes on March 4, 2026, warning that the flaw could let unauthenticated attackers execute arbitrary Java code as root on unpatched Secure FMC devices. The company urged customers to upgrade immediately.
The Interlock ransomware group started exploiting CVE-2026-20131, a maximum-severity insecure deserialization flaw in Cisco Secure Firewall Management Center, on or about January 26, 2026. The bug allowed unauthenticated remote code execution as root on affected devices before any public disclosure or patch was available.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
5 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcedarkreading.com
Open sourcecsoonline.com
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.