Interlock Ransomware Exploits Cisco FMC Zero-Day for Unauthenticated Root Access Since January
The Interlock ransomware group is actively exploiting CVE-2026-20131, a CVSS 10.0 insecure deserialization flaw in Cisco Firepower Management Center's web management interface, to achieve unauthenticated remote code execution as root. Amazon threat intelligence, using its MadPot honeypot network, identified exploitation in the wild since January 26—36 days before Cisco's March 4 disclosure. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on March 19. A misconfigured attacker server exposed Interlock's full operational toolkit including custom RATs and evasion tools. Separately, SentinelOne reports threat actors are exploiting FortiGate Next-Generation Firewall appliances (CVE-2025-59718, CVE-2025-59719, CVE-2026-24858) to extract configuration files containing encrypted LDAP credentials, decrypt them, and authenticate to Active Directory—activity consistent with an initial access broker targeting healthcare, government, and managed service providers.