Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Advisory/Mitigation Exploitation Wave Security Patch Release

Cisco FMC zero-day exploitation and KEV response

Updated 23.03.2026 12:30
Case score 69
Members 4 First seen 04.03.2026 21:12 Latest activity 23.03.2026 12:30

Overview

**Cisco Secure Firewall Management Center (FMC)** is under a zero-day exploitation wave centered on **CVE-2026-20131**, a deserialization flaw in the web-based management interface that can let an unauthenticated attacker execute Java code as root. Reporting tied the abuse to **Interlock** activity beginning on **January 26, 2026**, before Cisco's March 4 patch and before CISA moved the flaw into the **KEV** catalog. Cisco has already released fixes, and CISA ordered federal civilian agencies to remediate **CVE-2026-20131** by **March 22** or stop using FMC if mitigations are unavailable. The available evidence points to real exploitation pressure on a management-plane product, but it does not quantify how many deployments were hit or fully map the exposure footprint.
Latest development Open development history 3 earlier developments Interlock exploits Cisco FMC CVE-2026-20131 Interlock ransomware actors are reported to have exploited CVE-2026-20131 in attacks against Cisco Secure Firewall Management Center (FMC) starting January 26, using the web-based management interface to gain initial access before post-exploitation activity.
  1. Earlier development

    CISA orders patching of Cisco FMC CVE-2026-20131

    CISA ordered Federal Civilian Executive Branch (FCEB) agencies to apply security updates for CVE-2026-20131 in Cisco Secure Firewall Management Center (FMC) by Sunday, March 22 after Cisco updated its bulletin on March 18 to warn of active exploitation in the wild. Amazon threat intelligence researchers said Interlock ransomware had been exploiting CVE-2026-20131 as a zero-day since the end of January, and Cisco said the web-based management interface could let an unauthenticated, remote attacker execute arbitrary Java code as root on an affected device.

  2. Earlier development

    CISA adds CVE-2026-20131 to KEV

    CISA adds CVE-2026-20131 to its Known Exploited Vulnerabilities (KEV) catalog on Thursday 19 March and gives federal civilian agencies three days to patch Cisco Secure Firewall Management Center (FMC) or discontinue use if mitigations are unavailable, warning that the CVE is known to be used in ransomware campaigns.

  3. Earlier development

    Amazon reports Interlock exploitation of Cisco CVE-2026-20131

    Amazon threat intelligence reported that Interlock had been exploiting CVE-2026-20131 in attacks against enterprise firewalls before public disclosure and shared the findings with Cisco, while Cisco still had not flagged the flaw as actively exploited.

Signals

Exploitation
CVEs/products
Geographic context
Remediation
Threat context

Threat actor context

1 listed

Malware & tooling context

4 families · 5 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Vulnerability Cisco Secure Firewall Management Center (FMC) authentication bypass and RCE flaws (multiple vulnerabilities)
Updated 04.03.2026 21:12 Lead Contribution 66
Exploitation No Known Exploitation Exploit No Known Public Exploit CVSS 10.0 Critical Patch Patch Available

**Cisco Secure Firewall Management Center (FMC)** has two **maximum-severity** flaws, **CVE-2026-20079** and **CVE-2026-20131**, that can let **unauthenticated attackers** take over **unpatched devices**. One flaw can yield **root access** through crafted **HTTP requests**, and the other can execute **arbitrary Java code as root** via a crafted serialized Java object sent to the **web-based management interface**. Cisco released **security updates** on **March 4**, and the impact matters because FMC is the **administrative nerve center** for firewall policy and protection controls. **CISA** later added **CVE-2026-20131** to the **KEV catalog** and ordered **federal civilian agencies** to patch it quickly after reports of **active exploitation** and use in **ransomware campaigns**.

Exploitation Wave Interlock Cisco Secure Firewall Management Center zero-day exploitation wave
Updated 18.03.2026 18:53 Scoring Support Contribution 2
Exploitation Active Exploitation CVSS 10.0 Critical Patch Patch Available

A **zero-day exploitation wave** tied to **Interlock** has been hitting **Cisco Secure Firewall Management Center (FMC)**, putting **enterprise firewalls** at risk before patching. Cisco's **CVE-2026-20131** fix on **March 4** addressed a flaw that could let unauthenticated attackers run arbitrary Java code as root on unpatched devices. Amazon said the abuse began on **January 26, 2026**, giving attackers a head start before public disclosure.

Advisory/Mitigation CISA urgent mitigation order for Cisco FMC CVE-2026-20131
Updated 23.03.2026 12:30 Context
Exploitation Active Exploitation CVSS 10.0 Critical Urgency High Patch Patch Available

**CISA** ordered **federal civilian agencies** to patch **CVE-2026-20131** in **Cisco Secure Firewall Management Center (FMC)** within **three days** or discontinue use if mitigations are unavailable. The directive responds to an **actively exploited** **critical RCE** that can let an unauthenticated attacker run code as **root** on affected devices. CISA placed the vulnerability in its **KEV catalog** on **Thursday 19 March**, signaling urgent exposure across government deployments.

Security Patch Release Cisco Secure Firewall Management Center patch release (CVE-2026-20079, CVE-2026-20131)
Updated 04.03.2026 21:12 Context
Exploitation No Known Exploitation CVSS 10.0 Critical Urgency High Patch Patch Available

**Cisco Secure Firewall Management Center (FMC)** patch release for **CVE-2026-20131** and **CVE-2026-20079** addressed **CVSS 10** flaws that could let an **unauthenticated remote attacker** gain **root** or execute arbitrary code on affected devices. Cisco patched the issues on **March 4**, and later reporting said **Interlock ransomware** had been exploiting **CVE-2026-20131** as a **zero-day** for months, prompting **CISA** to order federal civilian agencies to patch by **March 22**.