CVE-2026-20131Active Exploitation(cisco / secure_firewall_management_center)

CRITICALCVSS 10.0 · CRITICALCISA KEV

Exploitation observed; activity peaked at 65 mentions and remains active

Immediate actions

  • Patch cisco secure_firewall_management_center systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-22. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-502

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • secure_firewall_management_center

Threat summary

  • Active exploitation appears in 202 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 290 mentions across 42 observed days

What's happening

  • Active exploitation reported across 202 signals
  • Exploit tool or code specified in 6 signals
  • PoC mentioned or linked in 9 signals
  • Patch or workaround mentioned in 100 signals
  • Technical details provided in 155 signals
  • Disclosure: 38 classified signals
  • Peaked 33d ago at 65 mentions (2026-03-19); latest day: 2
  • 290 total mentions across 42 days

Affected systems

Vendors
Products
secure_firewall_management_center

71 versions affected across 1 product

Deep dive

Activity timeline290 mentions / 42d
016334965Mentions · 2026-03-04: 9Mentions · 2026-03-05: 11Mentions · 2026-03-06: 2Mentions · 2026-03-07: 3Mentions · 2026-03-10: 1Mentions · 2026-03-11: 1Mentions · 2026-03-12: 1Mentions · 2026-03-18: 45Mentions · 2026-03-19: 65Mentions · 2026-03-20: 31Mentions · 2026-03-21: 19Mentions · 2026-03-22: 10Mentions · 2026-03-23: 13Mentions · 2026-03-24: 7Mentions · 2026-03-25: 8Mentions · 2026-03-26: 8Mentions · 2026-03-27: 3Mentions · 2026-03-29: 2Mentions · 2026-03-30: 3Mentions · 2026-03-31: 1Mentions · 2026-04-01: 1Mentions · 2026-04-02: 5Mentions · 2026-04-03: 1Mentions · 2026-04-06: 1Mentions · 2026-04-12: 1Mentions · 2026-04-15: 2Mentions · 2026-04-16: 2Mentions · 2026-04-17: 2Mentions · 2026-04-20: 1Mentions · 2026-04-21: 12Mentions · 2026-04-23: 2Mentions · 2026-04-27: 1Mentions · 2026-04-29: 1Mentions · 2026-05-05: 6Mentions · 2026-05-12: 1Mentions · 2026-05-14: 1Mentions · 2026-05-18: 1Mentions · 2026-06-03: 1Mentions · 2026-07-24: 1Mentions · 2026-08-04: 1Mentions · 2026-10-01: 1Mentions · 2026-10-08: 2PoC Mentioned / Linked · 2026-03-18: 1PoC Mentioned / Linked · 2026-03-19: 2PoC Mentioned / Linked · 2026-03-21: 1PoC Mentioned / Linked · 2026-03-22: 1PoC Mentioned / Linked · 2026-03-23: 1PoC Mentioned / Linked · 2026-03-25: 1PoC Mentioned / Linked · 2026-04-16: 1PoC Mentioned / Linked · 2026-05-05: 1Exploit Tool / Code · 2026-03-18: 2Exploit Tool / Code · 2026-03-23: 1Exploit Tool / Code · 2026-04-02: 1Exploit Tool / Code · 2026-05-05: 1Exploit Tool / Code · 2026-06-03: 1Active Exploitation · 2026-03-18: 42Active Exploitation · 2026-03-19: 58Active Exploitation · 2026-03-20: 27Active Exploitation · 2026-03-21: 11Active Exploitation · 2026-03-22: 8Active Exploitation · 2026-03-23: 8Active Exploitation · 2026-03-24: 5Active Exploitation · 2026-03-25: 5Active Exploitation · 2026-03-26: 6Active Exploitation · 2026-03-27: 3Active Exploitation · 2026-03-30: 2Active Exploitation · 2026-03-31: 1Active Exploitation · 2026-04-01: 1Active Exploitation · 2026-04-02: 4Active Exploitation · 2026-04-03: 1Active Exploitation · 2026-04-06: 1Active Exploitation · 2026-04-12: 1Active Exploitation · 2026-04-16: 2Active Exploitation · 2026-04-17: 2Active Exploitation · 2026-04-20: 1Active Exploitation · 2026-04-23: 2Active Exploitation · 2026-05-05: 6Active Exploitation · 2026-05-14: 1Active Exploitation · 2026-05-18: 1Active Exploitation · 2026-06-03: 1Active Exploitation · 2026-07-24: 1Active Exploitation · 2026-08-04: 1Patch / Workaround · 2026-03-04: 1Patch / Workaround · 2026-03-05: 7Patch / Workaround · 2026-03-06: 2Patch / Workaround · 2026-03-07: 2Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-03-18: 10Patch / Workaround · 2026-03-19: 20Patch / Workaround · 2026-03-20: 14Patch / Workaround · 2026-03-21: 10Patch / Workaround · 2026-03-22: 5Patch / Workaround · 2026-03-23: 8Patch / Workaround · 2026-03-24: 2Patch / Workaround · 2026-03-25: 3Patch / Workaround · 2026-03-26: 2Patch / Workaround · 2026-03-27: 2Patch / Workaround · 2026-03-29: 1Patch / Workaround · 2026-03-30: 1Patch / Workaround · 2026-03-31: 1Patch / Workaround · 2026-04-02: 4Patch / Workaround · 2026-04-03: 1Patch / Workaround · 2026-04-12: 1Patch / Workaround · 2026-04-17: 1Patch / Workaround · 2026-04-23: 1Technical Details · 2026-03-04: 7Technical Details · 2026-03-05: 10Technical Details · 2026-03-06: 2Technical Details · 2026-03-07: 2Technical Details · 2026-03-10: 1Technical Details · 2026-03-18: 18Technical Details · 2026-03-19: 31Technical Details · 2026-03-20: 15Technical Details · 2026-03-21: 13Technical Details · 2026-03-22: 8Technical Details · 2026-03-23: 8Technical Details · 2026-03-24: 5Technical Details · 2026-03-25: 4Technical Details · 2026-03-26: 6Technical Details · 2026-03-27: 1Technical Details · 2026-03-29: 1Technical Details · 2026-03-30: 3Technical Details · 2026-03-31: 1Technical Details · 2026-04-01: 1Technical Details · 2026-04-02: 5Technical Details · 2026-04-03: 1Technical Details · 2026-04-06: 1Technical Details · 2026-04-16: 1Technical Details · 2026-04-17: 1Technical Details · 2026-04-20: 1Technical Details · 2026-04-23: 2Technical Details · 2026-05-05: 1Technical Details · 2026-05-12: 1Technical Details · 2026-05-14: 1Technical Details · 2026-05-18: 1Technical Details · 2026-06-03: 1Technical Details · 2026-07-24: 103-0403-1003-1903-2303-2704-0104-1204-2004-2905-1810-0110-08
Signal classification5 categories
Active Exploitation
19266.9%
Disclosure
3813.2%
Patch
3110.8%
General
258.7%
PoC
10.3%
Referenced assets173 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-049
Disclosure6General2Patch1
2026-03-0511
Disclosure5Patch6
2026-03-062
Patch2
2026-03-073
Disclosure1Patch2
2026-03-101
Patch1
2026-03-111
General1
2026-03-121
General1
2026-03-1845
Active Exploitation42General3
2026-03-1965
Active Exploitation56Disclosure4General2Patch2PoC1
2026-03-2031
Active Exploitation25Disclosure1Patch5
2026-03-2119
Active Exploitation11Disclosure4General2Patch2
2026-03-2210
Active Exploitation8Disclosure2
2026-03-2313
Active Exploitation7Disclosure3General1Patch2
2026-03-247
Active Exploitation5Disclosure1General1
2026-03-258
Active Exploitation5Disclosure2Patch1
2026-03-268
Active Exploitation6Disclosure1Patch1
2026-03-273
Active Exploitation3
2026-03-292
General1Patch1
2026-03-303
Active Exploitation2Disclosure1
2026-03-311
Active Exploitation1
2026-04-011
Active Exploitation1
2026-04-025
Active Exploitation1Disclosure1Patch3
2026-04-031
Active Exploitation1
2026-04-061
Active Exploitation1
2026-04-121
Patch1
2026-04-152
General2
2026-04-162
Active Exploitation2
2026-04-172
Active Exploitation2
2026-04-201
Active Exploitation1
2026-04-2112
Disclosure6General6
2026-04-232
Active Exploitation1Patch1
2026-04-271
General1
2026-04-291
General1
2026-05-056
Active Exploitation6
2026-05-121
General1
2026-05-141
Active Exploitation1
2026-05-181
Active Exploitation1
2026-06-031
Active Exploitation1
2026-07-241
Active Exploitation1
2026-08-041
Active Exploitation1
Full discourse20 posts
  • Cyber Security News@The_Cyber_News
    Active Exploitation

    🚨 Cisco Firewall 0-day Vulnerability Exploited in the Wild to Deploy Interlock Ransomware Source: https://cybersecuritynews.com/cisco-firewall-0-day-ransomware/ An active campaign by the Interlock ransomware group is exploiting a critical zero-day vulnerability (CVE-2026-20131) in Cisco Secure Firewall Management Center (FMC) Software. The vulnerability may allow an unauthenticated remote attacker to execute arbitrary Java code with root privileges on an affected device. The investigation advanced when a misconfigured infrastructure server exposed Interlock’s complete operational toolkit. Initial threat activity involved HTTP requests to a vulnerable software path, containing Java code execution attempts and embedded URLs. #cybersecuritynews #cisco

    Post summary

    Cisco Secure Firewall Management Center is being exploited in the wild by Interlock ransomware, leveraging the zero‑day CVE-2026-20131 to execute arbitrary Java code with root privileges.

    56041825211.0K
    51.4K followersView on X
  • Hunter@HunterMapping
    Disclosure

    🚨Alert🚨 CVE-2026-20131 (CVSS 10.0) : Critical Flaw in Cisco Secure FMC Hands Hackers Root Access to Enterprise Firewalls 📊 62K+ Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22Cisco%20Secure%20Firewall%20Management%20Center%22 👇Query HUNTER : http://product.name="Cisco Secure Firewall Management Center" 📰Refer:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh https://www.bleepingcomputer.com/news/security/cisco-warns-of-max-severity-secure-fmc-flaws-giving-root-access/ https://securityonline.info/critical-10-0-cvss-flaw-in-cisco-secure-fmc-hands-hackers-root-access-to-enterprise-firewalls/ #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    The post announces a critical CVE-2026-20131 affecting Cisco Secure FMC, providing CVSS and RCE details, but does not include PoC, exploit code, active use, or patch information.

    223048164.4K
    25.5K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Active Exploitation

    صدر اليوم تحذير بخصوص ثغرة في "Cisco Secure Firewall Management Center (FMC)" برقم (CVE-2026-20131) وبتقييم خطورة (10/10). الأخبار "المقلقة" تقول إن الثغرة يتم استغلالها فعلياً (Zero-day) منذ شهر يناير الماضي، يعني قبل الإعلان الرسمي بأسابيع. وش تفاصيل الثغرة؟ 🔵 المشكلة في معالجة البيانات (Insecure Deserialization)؛ وهذا يسمح للمهاجم بإرسال طلبات (HTTP) مُعدة خصيصاً لتنفيذ أكواد Java خبيثة. 🔵 الخطورة هنا أن المهاجم لا يحتاج أي صلاحيات دخول (No Authentication)، وبمجرد الدخول يقدر يوصل لصلاحيات (Root) كاملة على الجهاز. تطورات الهجوم: 🔵 رصدت بعض الباحثين مجموعة (Interlock) وهي تستخدم الثغرة لزرع برمجيات تجسس وتحويل السيرفرات إلى (Proxies) لتغطية نشاطهم الإجرامي. 🔵 الثغرة استُغلت في "الخفاء" لفترة طويلة، وهذا يعني أن مجرد التحديث الآن قد لا يكون كافياً إذا كان النظام قد اختُرق مسبقاً. 💡 نصيحة: 1- الأولوية الآن هي تحديث أنظمة FMC لأحدث إصدار فوراً. 2- مراجعة سجلات الدخول (Logs) من نهاية شهر يناير للتأكد من عدم وجود أي نشاط مشبوه سابق.

    Post summary

    The post warns that CVE‑2026‑20131 in Cisco Secure Firewall Management Center is being actively exploited as a zero‑day since January via insecure deserialization, and urges immediate patching and log review to mitigate the risk.

    02048239.1K
    47.2K followersView on X
  • Nicolas Krassas@Dinosn
    Active Exploitation

    Interlock Ransomware Exploits Cisco FMC Zero-Day CVE-2026-20131 for Root Access https://www.bleepingcomputer.com/news/security/interlock-ransomware-exploited-secure-fmc-flaw-in-zero-day-attacks-since-january/

    Post summary

    Interlock ransomware has successfully leveraged the zero‑day CVE‑2026‑20131 in Cisco FMC to gain root privileges in the wild.

    01103062.9K
    153.3K followersView on X
  • CISA Cyber@CISACyber
    General

    🛡️ We added Cisco Secure Firewall Management Center software and Security Cloud Control vulnerability CVE-2026-20131 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q for more information. #Cybersecurity #InfoSec https://t.co/bTfjUOA1dx

    Post summary

    The tweet announces that CVE‑2026‑20131 has been added to the KEV catalog, directing readers to a DHS link for more information, but it provides no technical details or evidence of exploitation.

    11103035.7K
    293.0K followersView on X
  • elhacker.NET@elhackernet
    Active Exploitation

    [Blog] Ransomware Interlock explota Zero-Day crítico en Cisco FMC (CVE-2026-20131) https://blog.elhacker.net/2026/03/ransomware-interlock-explota-zero-day.html

    Post summary

    The blog post announces that ransomware Interlock is exploiting a critical zero‑day (CVE‑2026‑20131) in Cisco FMC, indicating real‑world usage but providing no PoC, patch, or detailed technical information.

    01002162.6K
    138.5K followersView on X
  • Gray Hats@the_yellow_fall
    Active Exploitation

    Interlock ransomware weaponized a Cisco zero-day (CVE-2026-20131) weeks before detection. Learn how they used fileless web shells and Java RCE in 2026. https://meterpreter.org/the-interlock-chronicles-how-a-cisco-zero-day-fueled-a-month-long-ransomware-rampage/ https://t.co/LhWxZJaopz

    Post summary

    The tweet reports that Interlock ransomware weaponized Cisco CVE‑2026‑20131 weeks before it was detected, illustrating active real‑world exploitation of the zero‑day.

    1801681.1K
    10.7K followersView on X
  • Nicolas Krassas@Dinosn
    Active Exploitation

    Interlock Ransomware Exploits Cisco FMC Zero-Day CVE-2026-20131 for Root Access https://thehackernews.com/2026/03/interlock-ransomware-exploits-cisco-fmc.html

    Post summary

    Interlock ransomware is reported to exploit Cisco FMC's zero‑day CVE-2026-20131 to gain root access, indicating active use in the wild.

    0301552.2K
    153.3K followersView on X
  • Gray Hats@the_yellow_fall
    Active Exploitation

    Amazon threat intel reveals Interlock ransomware is actively exploiting a critical 10.0 CVSS Cisco zero-day (CVE-2026-20131) to hijack firewall networks. #InterlockRansomware #ZeroDay #CiscoSecurity #CVE #CyberSecurity #InfoSec #Ransomware https://securityonline.info/exploited-in-wild-interlock-ransomware-cisco-zero-day-cve-2026-20131/ https://t.co/PhWBPUQqRC

    Post summary

    The tweet reports that Interlock ransomware is actively exploiting the Cisco CVE‑2026‑20131 zero‑day, but no PoC, exploit code, or patch details are provided.

    04095860
    10.7K followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    CVE-2026-20131 (CVSS 10) Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh

    Post summary

    Cisco announced CVE-2026-20131, a CVSS 10 Remote Code Execution flaw in Secure Firewall Management Center. A vendor advisory link is provided for more details.

    0101071.5K
    152.3K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(3/19追加) 🛡️No.1547 CVE-2026-20131 Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability ===================================== ✅概要 ・深刻度:緊急🔥 10.0 (CVSS Base) / Cisco (CNA) ・種別:信頼できないデータのデシリアライゼーション (CWE-502) ・CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H 事前認証されていない攻撃者がリモートから任意コード実行を行う可能性がある脆弱性。 ✅ChatGPTによる脆弱性評価 ・国内影響度判定:高 ・悪用難易度:低 ✅攻撃前提条件 ・対象システムへネットワーク経由で到達可能 ・脆弱な FMC / SCC バージョンが稼働 ✅悪用時影響 ・未認証での任意コード実行 ・管理基盤の完全掌握 ・ファイアウォールポリシーの改ざん ・ネットワーク全体への侵害拡大 ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開済み ・ITW:CISAがランサムウエア事案での悪用を確認 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-20131 https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/ https://www.cisa.gov/news-events/alerts/2026/03/19/cisa-adds-one-known-exploited-vulnerability-catalog #vulnerability

    Post summary

    CISA confirmed active exploitation of CVE‑2026‑20131, a deserialization vulnerability in Cisco FMC/SCC that allows unauthenticated remote code execution; PoC/exploit is already published and vendor advisory links are provided.

    0501004.3K
    42.8K followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Disclosure

    Ciscoのセキュリティアドバイザリが公開されていますね。criticalは2件。 https://sec.cloudapps.cisco.com/security/center/publicationListing.x ▼参考 Cisco warns of max severity Secure FMC flaws giving root access https://www.bleepingcomputer.com/news/security/cisco-warns-of-max-severity-secure-fmc-flaws-giving-root-access/ 『(直訳)認証バイパスの脆弱性 ( CVE-2026-20079 ) により、攻撃者は基盤となるオペレーティング システムのルート アクセスを取得できます。一方、リモート コード実行 (RCE) の脆弱性 ( CVE-2026-20131 ) により、パッチが適用されていないデバイスで攻撃者がルートとして任意の Java コードを実行できます。』

    Post summary

    Cisco’s security advisory announces two critical vulnerabilities—CVE‑2026‑20079 (auth bypass granting root access) and CVE‑2026‑20131 (remote code execution allowing arbitrary Java code as root on unpatched devices).

    020701.3K
    11.3K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Interlock ransomware group pivots from user-driven attacks to zero-day exploitation, deploying AI-generated Slopoly backdoor to bypass security controls. Active campaign exploited Cisco FMC vulnerability for 36 days before patching. Key technical details: • CVE-2026-20131: Zero-day in Cisco Secure FMC enabling root RCE via crafted HTTP requests with serialized Java • Slopoly backdoor: AI-generated PowerShell C2 framework with WebSocket persistence and real-time communication • Hotta Killer: Custom utility exploiting CVE-2025-61155 in GameDriverX64.sys for kernel-level EDR disabling (T1685) • Memory-resident Java webshells intercept HTTP requests, decrypt commands, execute in-memory to evade AV • LOLBAS abuse: BITSAdmin, PowerShell, AZCopy for staging, lateral movement, and Azure Blob exfiltration (T1567.002) Attack chain methodology: • Phase 1: Shifted from drive-by downloads to direct infrastructure targeting via network edge vulnerabilities • Phase 2-3: Volatility for credential extraction, Certipy for AD CS privilege escalation, NetSupport RAT deployment • Phase 4-5: Advanced Port Scanner reconnaissance, RDP pivoting to DCs/Exchange, HAProxy nodes for exfiltration masking • Phase 6: PsExec domain-wide ransomware deployment with .interlock extension and !__README__!.txt notes Hunt for AZCopy activity to unfamiliar Azure destinations, NetSupport/AnyDesk from servers, and recurring /api/commands HTTP beaconing patterns. #DFIR_Radar

    Post summary

    The post reports an active exploitation campaign using zero‑day CVEs, detailing the tools and tactics employed, with no evidence of misinformation or patches beyond a generic mention of post‑incident patching.

    10031708
    1.8K followersView on X
  • Una al día@unaaldia
    Active Exploitation

    Ransomware Interlock explota Zero-Day crítico en Cisco FMC (CVE-2026-20131) https://unaaldia.hispasec.com/2026/03/ransomware-interlock-explota-zero-day-critico-en-cisco-fmc-cve-2026-20131.html

    Post summary

    The headline reports that the Interlock ransomware is exploiting the critical zero‑day CVE‑2026‑20131 on Cisco FMC, with no patch or mitigation details provided.

    02021413
    17.3K followersView on X
  • Mr.Rabbit@01ra66it
    Active Exploitation

    Interlockは、Cisco Secure Firewall Management Centerの最大深刻度RCE CVE-2026-20131 を、公開前からゼロデイとして悪用していた。重要なのは、2026年1月26日から使われており、Ciscoが3月4日に修正を出すまで36日間、未対策の企業ファイアウォールを直接狙えた点。 この脆弱性は、未認証で任意のJavaコードをroot権限で実行できるもので、Ciscoは3月4日に修正。BleepingComputerによると、Amazonの脅威調査チームがInterlockの実際の悪用を確認している。Interlock自体は2024年9月以降のランサム運用で、ClickFix、NodeSnake、最近ではSlopolyとも関連付けられている。 APT: Interlock Malware: NodeSnake, Slopoly, Interlock ransomware CVE: CVE-2026-20131 IoC: Cisco Secure FMC, unauthenticated Java RCE as root, exploitation since 2026-01-26, patch released 2026-03-04 #CyberSecurity #ThreatIntel #Ransomware #Interlock #Cisco #ZeroDay https://www.bleepingcomputer.com/news/security/interlock-ransomware-exploited-secure-fmc-flaw-in-zero-day-attacks-since-january/

    Post summary

    The post confirms that CVE‑2026‑20131, an unauthenticated Java RCE in Cisco Secure FMC, has been actively exploited by Interlock ransomware since January 26, 2026, with Cisco patching the issue on March 4, 2026.

    00041646
    3.4K followersView on X
  • Ian Bell@ibell63
    Disclosure

    I'm not a vulnerability researcher, but on the basis where there's one vulnerability, there's probably more of the same type; probably some Cisco security appliance, again: CVE-2026-20131 is pretty wild: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh TL;DR: The firewall's management plane (FMC), which shouldn't be exposed to the Internet will run a serialized Java bytestream from an unauthenticated user as root if you send it the right way. It scores 10.0 on CVSS V3.1. If this vulnerability existed, that frankly means that other things are also probably NOT well designed inside.

    Post summary

    The post points to Cisco’s 2026-20131 RCE vulnerability, describing the flaw and CVSS score but offers no proof of exploitation or patch details.

    20011222
    61 followersView on X
  • Raúl León @rleon_mx
    Active Exploitation

    Grupos de ransomware explotaron la vulnerabilidad CVE-2026-20131, un fallo de severidad grave en el software de Cisco. Esta falla permite a un atacante remoto no autenticado ejecutar código Java arbitrario como usuario root en dispositivos vulnerables. https://www.theregister.com/2026/03/18/amazon_cisco_firewall_0_day_ransomware/ https://t.co/9k2OZGUmCC

    Post summary

    Ransomware groups have actively exploited the critical Cisco software vulnerability CVE-2026-20131, enabling unauthenticated remote Java code execution as root; no PoC, exploit code, or patch is referenced in the text.

    01021237
    6.3K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Interlock ransomware (GOLD EMBRACE) weaponizes Volatility3 and WinPmem for in-memory credential dumping, moves from ClickFix lure to domain controller in 26 hours, exploiting Cisco zero-day CVE-2026-20131. Key findings: - Initial access via ClickFix social engineering (T1189): user clicked a ChatGPT-referred result, clipboard was read within 5 seconds, then pasted a command pulling PowerShell from afshapiro[.]com, which curl-fetched NodeSnake RAT from 104.236.109[.]139, persisting via Registry Run key (T1547.001). C2 resolved to voginc[.]com at 64.95.11[.]22. - Interlock used winpmem_mini_x64_rc2.exe to capture a raw memory image (mem.raw), then ran vol.exe against it for hashdump (NTLM/LM) and cachedump (cached domain creds). This is the artifact: mem.raw plus vol.exe on a non-DFIR system is adversarial, not investigative. - Privilege escalation chain: PE injection via zoom.txt (T1055.002), Kerberoasting via SPN query (T1134.003), then RDP lateral movement to DC using NTLM downgrade (T1021.001), all within 26 hours of first click. - Scheduled task persistence on print server masqueraded as ScheduledDefrags, running debug.log via node.exe from AppData\Roaming\node-v22.11.0-win-x64. Key detections: JS/Agent-BLXU (node.log), Troj/Ransom-HKG (Win64.exe), Troj/Ilocrypt-A (dll.dll, NtlmThief). C2: browser-updater[.]com, hxxp://216.203.20[.]36/debug[.]log. #DFIR_Radar

    Post summary

    Interlock ransomware is actively exploiting Cisco CVE‑2026‑20131, utilizing memory‑dumping tools and credential‑dumping techniques, demonstrating real‑world use in attacks.

    11001226
    1.8K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2024-32002 2 - CVE-2025-20333 3 - CVE-2026-20131 4 - CVE-2026-33626 5 - CVE-2024-57726 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists a set of trending CVE identifiers with no additional context, such as technical details, exploitation status, or remediation information.

    00021725
    1.7K followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    Cisco FMC のゼロデイ脆弱性 CVE-2026-20131:Interlock ランサムウェアが実環境で悪用 https://iototsecnews.jp/2026/03/18/cisco-firewall-0-day-vulnerability-exploited-in-the-wild-to-deploy-interlock-ransomware/ 訳者後書:今回のインシデントにおける侵入経路は、Cisco Secure Firewall Management Center (FMC) における深刻なゼロデイ脆弱性 CVE-2026-20131 の悪用によるものです。この問題の原因は、認証を受けていないリモートの攻撃者が、最高権限である root 権限で任意の Java コードを実行できてしまうという、ソフトウェア上の不備にあります。攻撃グループが使用するインフラ・サーバの設定に不適切な箇所があったことで、彼らの高度な運用ツールキットが露出し、実態の解明へとつながりました。この脆弱性は CISA KEV にも登録され、Date Added: 2026-03-19/Due Date: 2026-03-22 という、きわめて厳しい期限が設定されています。ご利用のチームは、ご注意ください。 #Cisco #CVE202620131 #FMC #SecureFirewallManagementCenter #Vulnerability #ZeroDay

    Post summary

    CVE-2026-20131 enables unauthenticated remote code execution at root in Cisco FMC, and is actively exploited to deploy Interlock ransomware; no PoC, exploit code, or patch is disclosed.

    01011181
    481 followersView on X
CPE platform detail71 entries

71 of 71 entries

PartVendorProductVersionTarget SWTarget HW
Appciscosecure_firewall_management_center10.0.0--
Appciscosecure_firewall_management_center6.4.0.13--
Appciscosecure_firewall_management_center6.4.0.14--
Appciscosecure_firewall_management_center6.4.0.15--
Appciscosecure_firewall_management_center6.4.0.16--
Appciscosecure_firewall_management_center6.4.0.17--
Appciscosecure_firewall_management_center6.4.0.18--
Appciscosecure_firewall_management_center7.0.0--
Appciscosecure_firewall_management_center7.0.0.1--
Appciscosecure_firewall_management_center7.0.1--
Appciscosecure_firewall_management_center7.0.1.1--
Appciscosecure_firewall_management_center7.0.2--
Appciscosecure_firewall_management_center7.0.2.1--
Appciscosecure_firewall_management_center7.0.3--
Appciscosecure_firewall_management_center7.0.4--
Appciscosecure_firewall_management_center7.0.5--
Appciscosecure_firewall_management_center7.0.6--
Appciscosecure_firewall_management_center7.0.6.1--
Appciscosecure_firewall_management_center7.0.6.2--
Appciscosecure_firewall_management_center7.0.6.3--
Appciscosecure_firewall_management_center7.0.7--
Appciscosecure_firewall_management_center7.0.8--
Appciscosecure_firewall_management_center7.0.8.1--
Appciscosecure_firewall_management_center7.1.0--
Appciscosecure_firewall_management_center7.1.0.1--
Appciscosecure_firewall_management_center7.1.0.2--
Appciscosecure_firewall_management_center7.1.0.3--
Appciscosecure_firewall_management_center7.2.0--
Appciscosecure_firewall_management_center7.2.0.1--
Appciscosecure_firewall_management_center7.2.1--
Appciscosecure_firewall_management_center7.2.10--
Appciscosecure_firewall_management_center7.2.10.1--
Appciscosecure_firewall_management_center7.2.10.2--
Appciscosecure_firewall_management_center7.2.2--
Appciscosecure_firewall_management_center7.2.3--
Appciscosecure_firewall_management_center7.2.3.1--
Appciscosecure_firewall_management_center7.2.4--
Appciscosecure_firewall_management_center7.2.4.1--
Appciscosecure_firewall_management_center7.2.5--
Appciscosecure_firewall_management_center7.2.5.1--
Appciscosecure_firewall_management_center7.2.5.2--
Appciscosecure_firewall_management_center7.2.6--
Appciscosecure_firewall_management_center7.2.7--
Appciscosecure_firewall_management_center7.2.8--
Appciscosecure_firewall_management_center7.2.8.1--
Appciscosecure_firewall_management_center7.2.9--
Appciscosecure_firewall_management_center7.3.0--
Appciscosecure_firewall_management_center7.3.1--
Appciscosecure_firewall_management_center7.3.1.1--
Appciscosecure_firewall_management_center7.3.1.2--
Appciscosecure_firewall_management_center7.4.0--
Appciscosecure_firewall_management_center7.4.1--
Appciscosecure_firewall_management_center7.4.1.1--
Appciscosecure_firewall_management_center7.4.2--
Appciscosecure_firewall_management_center7.4.2.1--
Appciscosecure_firewall_management_center7.4.2.2--
Appciscosecure_firewall_management_center7.4.2.3--
Appciscosecure_firewall_management_center7.4.2.4--
Appciscosecure_firewall_management_center7.4.3--
Appciscosecure_firewall_management_center7.4.4--
Appciscosecure_firewall_management_center7.4.5--
Appciscosecure_firewall_management_center7.6.0--
Appciscosecure_firewall_management_center7.6.1--
Appciscosecure_firewall_management_center7.6.2--
Appciscosecure_firewall_management_center7.6.2.1--
Appciscosecure_firewall_management_center7.6.3--
Appciscosecure_firewall_management_center7.6.4--
Appciscosecure_firewall_management_center7.7.0--
Appciscosecure_firewall_management_center7.7.10--
Appciscosecure_firewall_management_center7.7.10.1--
Appciscosecure_firewall_management_center7.7.11--

Explore more