Cisco FMC flaw was exploited by Interlock weeks before patch (CVE-2026-20131)
2026-03-20T14:51:53Z•300edb502ee76b1cb0e6751b4083a6e5fbac0bb9c0575da77ba8160903f8ced3
AI access managementAndroid sideloadingCVE-2026-20131CVE-2026-3564Cisco FMCConnectWiseDDoSDSPMInterlockIoT botnetsScreenConnectSemgrepcloud securitycode securitycyber extortiondata protectionlaw enforcementransomwareremote accessscam preventionstreaming fraudzero-day
What happened
Multiple high‑impact security stories: A critical zero‑day in Cisco Secure Firewall Management Center (CVE-2026-20131) was actively exploited by the Interlock ransomware gang beginning Jan 26, 2026—36 days before Cisco’s public disclosure and patch, according to Amazon’s MadPot honeypot telemetry. Separately, ConnectWise patched a critical ScreenConnect flaw (CVE-2026-3564) that allowed remote forging of authentication via ASP.NET machine keys, enabling session hijacking. Law enforcement disrupted four large IoT botnets tied to record DDoS attacks (up to ~30 Tbps). Other notable items: Googleʼ
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- 300edb502ee76b1cb0e6751b4083a6e5fbac0bb9c0575da77ba8160903f8ced3
- Enrichment time
- 2026-03-20T14:51:53Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.