Cybersecurity & Privacy — 2026-03-23

CISA Orders Federal Agencies to Patch Max-Severity Cisco FMC Flaw Exploited by Interlock Ransomware

CISA ordered federal agencies to patch CVE-2026-20131, a maximum-severity vulnerability in Cisco Secure Firewall Management Center, by March 22. The Interlock ransomware gang has exploited the flaw as a zero-day since late January. CISA also added five additional KEV entries on March 20 covering Apple, Craft CMS, and Laravel Livewire flaws. The Cisco FMC vulnerability is particularly dangerous because it provides attackers with root-level access to firewall management infrastructure.

2 sources
  1. CISA orders feds to patch max-severity Cisco flaw by Sunday - BleepingComputer
  2. CISA Adds Five Known Exploited Vulnerabilities to Catalog

View in full brief →

UNCLASSIFIED // OPEN SOURCE