DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-20131PUBLISHED: 2026-03-04
CRITICALCVE-2026-20131★ CISA KEV LISTED

Cisco Secure FMC Insecure Deserialization Unauthenticated RCE

VENDOR: Cisco//PRODUCT: Cisco Secure Firewall Management Center (FMC) Software
10
CRITICAL
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
PUBLIC EXPLOIT

An insecure deserialization of a user-supplied Java byte stream in the FMC web management interface allows an unauthenticated, remote attacker to execute arbitrary Java code as root. The Interlock ransomware group actively exploited this as a zero-day beginning January 26, 2026 — 36 days before Cisco's official disclosure — targeting education, healthcare, manufacturing, and government sectors. Nine public PoC/exploits are available on GitHub; Zscaler ThreatLabz observed active exploitation payloads using the public PoC starting March 6, 2026. Advisory updated July 29, 2026 with new IoCs shared with CVE-2026-20316.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
NONE
User Interaction
NONE
Scope / Impact
CHANGED
C:H · I:H · A:H
AFFECTED VERSIONSCisco Secure FMC Software versions 6.4.0.13 through 7.7.11; Cisco Security Cloud Control (SCC) Firewall Management
  • https://www.zscaler.com/blogs/security-research/critical-remote-code-execution-vulnerability-cisco-secure-firewall
  • https://thehackernews.com/2026/03/interlock-ransomware-exploits-cisco-fmc.html
  • https://horizon3.ai/attack-research/vulnerabilities/cve-2026-20131/
  • https://www.bleepingcomputer.com/news/security/cisco-warns-of-fmc-static-credential-flaw-exploited-in-zero-day-attacks/
SHARE BRIEF:✕ Post on Xin Share on LinkedIn