Ransomware actor exploited critical Cisco Secure Firewall Management Center flaw
Amazon's threat intelligence team has described an Interlock ransomware campaign exploiting a critical vulnerability in Cisco Secure Firewall Management Center. The flaw, CVE-2026-20131, stems from improper handling of serialized Java objects and lets an attacker send crafted requests to the FMC interface and execute arbitrary code with high privileges, often at root level. Exploitation began on 26 January, and Cisco released a patch on 4 March.
What this means for your organisation
The firewall management platform is among the most central systems in the infrastructure, and control over it lets an attacker rewrite the security architecture itself. The timeline is worth noting: exploitation ran for roughly five weeks before a patch existed. Patching alone is therefore not enough, and organisations that exposed this interface should consider whether they were already affected.
Berigo recommends
- Apply Cisco's patch for CVE-2026-20131 and confirm it is actually running on every instance.
- Remove the management interface from the internet and restrict access to defined administration networks.
- Review logs back to late January for signs of unauthorised access and configuration changes.
- Rotate credentials and keys tied to the platform if exposure cannot be ruled out.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch