Interlock Ransomware Exploits Cisco Zero-Day CVE-2026-20131
The Interlock ransomware gang has been actively exploiting a zero-day vulnerability, CVE-2026-20131, in Cisco's Firepower Management Center (FMC) to gain root access. This maximum severity remote code execution (RCE) vulnerability has been under attack since January, allowing adversaries to compromise affected systems. Security teams should prioritize patching and review network activity for indicators of compromise, as this vulnerability poses a significant risk to organizational security.