Cisco FMC zero-day exploitation and KEV response
Case score 69
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 69
- Main story score
- 66
- Related evidence lift
- +3 / 20
- Contributing updates
- 1
- Context updates
- 2
- Vulnerability Base event: maximum-severity FMC flaw with remote root-level compromise risk. main
- Advisory Mitigation Adds the CISA KEV listing and the federal remediation deadline for the same CVE. context
- Security Patch Release Adds Cisco's March 4 patch release and confirms SCC Firewall Management is also affected. context
- Exploitation Wave Adds active exploitation reporting tied to Interlock and a zero-day abuse timeline that began before patching. contributes
Overview
Latest development Open development history Interlock exploits Cisco FMC CVE-2026-20131 Interlock ransomware actors are reported to have exploited CVE-2026-20131 in attacks against Cisco Secure Firewall Management Center (FMC) starting January 26, using the web-based management interface to gain initial access before post-exploitation activity.
-
CISA orders patching of Cisco FMC CVE-2026-20131
CISA ordered Federal Civilian Executive Branch (FCEB) agencies to apply security updates for CVE-2026-20131 in Cisco Secure Firewall Management Center (FMC) by Sunday, March 22 after Cisco updated its bulletin on March 18 to warn of active exploitation in the wild. Amazon threat intelligence researchers said Interlock ransomware had been exploiting CVE-2026-20131 as a zero-day since the end of January, and Cisco said the web-based management interface could let an unauthenticated, remote attacker execute arbitrary Java code as root on an affected device.
-
CISA adds CVE-2026-20131 to KEV
CISA adds CVE-2026-20131 to its Known Exploited Vulnerabilities (KEV) catalog on Thursday 19 March and gives federal civilian agencies three days to patch Cisco Secure Firewall Management Center (FMC) or discontinue use if mitigations are unavailable, warning that the CVE is known to be used in ransomware campaigns.
-
Amazon reports Interlock exploitation of Cisco CVE-2026-20131
Amazon threat intelligence reported that Interlock had been exploiting CVE-2026-20131 in attacks against enterprise firewalls before public disclosure and shared the findings with Cisco, while Cisco still had not flagged the flaw as actively exploited.