Cybersecurity & Privacy — 2026-03-23
CISA Orders Federal Agencies to Patch Max-Severity Cisco FMC Flaw Exploited by Interlock Ransomware
CISA ordered federal agencies to patch CVE-2026-20131, a maximum-severity vulnerability in Cisco Secure Firewall Management Center, by March 22. The Interlock ransomware gang has exploited the flaw as a zero-day since late January. CISA also added five additional KEV entries on March 20 covering Apple, Craft CMS, and Laravel Livewire flaws. The Cisco FMC vulnerability is particularly dangerous because it provides attackers with root-level access to firewall management infrastructure.