INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Cisco FMC Vulnerability Exploit Found in Max-Severity Flaw

| 2026-03-20 15:09 CRITICAL HIGH
Executive Summary AI-generated
The threat actor behind the Interlock ransomware has been exploiting a zero-day vulnerability in Cisco's Secure Firewall Management Center (FMC) software, known as CVE-2026-20131. The vendor had identified this flaw months prior to its publication and added it to their Known Exploited Vulnerabilities catalog on March 20th. However, the threat actor was able to exploit it before a patch could be released by Sunday, March 22nd. This has put federal agencies under pressure to apply security updates or stop using the product as soon as possible. The vendor's advisory warns of an unauthenticated remote attacker who can execute arbitrary Java code on affected devices via the vulnerable web-based management interface.
Technical Mitigations AI-generated
* Implement a secure deserialization mechanism to prevent insecure deserialization of user-supplied Java byte streams, which can be exploited by sending crafted serialized Java objects. * Regularly review and update software dependencies to ensure that all affected systems have the latest patches and updates for Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management. * Monitor system logs and network traffic for signs of unauthorized access or malicious activity, and take prompt action if any suspicious behavior is detected. * Consider implementing a web application firewall (WAF) to detect and block potential attacks on the Cisco Secure Firewall Management Center (FMC) Software interface.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-20131CVE-2026-20131 CVE-2026-20079CVE-2026-20079
Target & Sectors
Global Scope healthhealth technologytechnology defensedefense
Incident Timeline
late 2024
Threat actors used a Cisco interconnect flaw to target Kettering Health.
industry Health
tactic Ransomware
organisation Kettering Health
organisation Texas Tech University System
September 2024
The Interlock ransomware group threatened to disrupt the operations of DaVita and Kettering Health unless a critical Cisco vulnerability was patched by Sunday.
industry Health
tactic Ransomware
organisation Kettering Health
organisation Texas Tech University
late January 2026
Threat actors used a recently disclosed Cisco vulnerability to target Federal Civilian Executive Branch agencies.
vulnerability CVE-2026-20131
attribution FCEB
attribution CISA
attribution Federal Civilian Executive Branch
January 2026
CISA ordered the federal government to patch a max-severity Cisco flaw by Sunday.
organisation The Red Report 2026
January 26, 2026
Threat actors exploited the CVE-2026-20131 flaw 36 days before its public disclosure, targeting Amazon researchers starting on January 26, 2026.
vulnerability CVE-2026-20131
organisation Amazon
organisation Interlock
2026-02-02
CISA ordered the patching of a max-severity Cisco flaw in Catalyst SD-WAN by Sunday.
organisation Catalyst SD-WAN
March 4
Threat actors used a Cisco vulnerability to target affected systems.
2026-03-04
Threat actors used Cisco's patching software to target Defense organizations with max-severity vulnerabilities.
industry Defense
general_metric 15 severity security flaws
March 18
The US Cybersecurity and Infrastructure Security Agency (CISA) ordered the federal government to patch a critical vulnerability in Cisco systems by Sunday.
vulnerability CVE-2026-20131
2026-03-20
The threat actors used the Interlock ransomware group to exploit a critical zero-day vulnerability in Cisco Secure FMC's web interface.
infrastructure 10.0
organisation Amazon
organisation CVE-2026
organisation Cisco Security Cloud Control (SCC
organisation Cisco Secure FMC
organisation Cisco Secure Firewall Management Center
organisation Cisco Secure FMC’s
organisation The Cisco Secure Firewall Management Center
organisation ClickFix
organisation NodeSnake
organisation Secure FMC
organisation Cisco
organisation Secure Firewall Management Center
organisation SSH
organisation FMC
organisation SecurityAffairs
organisation Product Security Incident Response Team
organisation PoC
organisation Unified Communications
organisation CyberScoop
March 22, 2026
Threat actors are expected to exploit a max-severity Cisco vulnerability by Sunday.
March 22
The US Department of Homeland Security (DHS) ordered federal agencies to patch the maximum-severity vulnerability CVE-2026-20131 in Cisco Secure Firewall Management Center by Sunday, March 22.
vulnerability CVE-2026-20131
attribution Cisco Secure Firewall Management Center
attribution CVE-2026
early March 2026
Threat actors exploited a max-severity Cisco vulnerability and notified The National Cybersecurity Alliance (CISA) by early March 2026.
Tactical Metrics
Metrics
infrastructure
​10.0
Software Version