Interlock ransomware exploited Cisco FMC zero-day CVE-2026-20131

by

An Amazon Threat Intelligence report links an active Interlock ransomware campaign to exploitation of a critical Cisco Secure Firewall Management Center vulnerability tracked as CVE-2026-20131 and rated CVSS 10.0, with exploitation observed from January 26, 2026.

KEY FACTS

  • Vulnerability CVE-2026-20131 insecure deserialization allows unauthenticated remote root code execution
  • Zero-day window Exploitation tracked from January 26, 2026, before public disclosure
  • Actor Interlock ransomware group linked by convergent indicators
  • Tools Bespoke RATs, web shells, recon scripts, ScreenConnect, and proxy tooling

The flaw allows an unauthenticated remote attacker to submit a crafted Java byte stream that is insecurely deserialized, enabling arbitrary Java code execution as root on an affected device.

The attack chain uses crafted HTTP requests to a specific FMC path to execute Java code. After successful exploitation the compromised system issues an HTTP PUT to an external server to confirm success and then fetches an ELF binary that delivers additional tooling.

Tools included a PowerShell reconnaissance script for detailed Windows enumeration, custom remote access trojans written in JavaScript and Java with file transfer and SOCKS5 proxy features, a Bash script that configures Linux reverse proxies with fail2ban and HAProxy and purges logs, a memory resident web shell that accepts encrypted command payloads, a lightweight network beacon, ConnectWise ScreenConnect for persistence, and the Volatility memory forensics framework.

Evidence tying the operation to Interlock includes an embedded ransom note and a TOR negotiation portal. The actor’s toolkit was exposed by a misconfigured infrastructure server and activity appears aligned with the UTC+3 time zone.

Users are advised to apply vendor patches immediately, perform security assessments to detect compromise, review any ScreenConnect deployments for unauthorized installations, and implement defense in depth to reduce risk during zero-day windows.

WHY IT MATTERS

Zero-day exploitation against firewall management software can give attackers rapid, high privilege access to networks. Timely patching and layered security controls help narrow the window of exposure and limit impact.