Cisco FMC flaw was exploited by Interlock weeks before patch (CVE-2026-20131)

2026-03-20T14:51:53Z300edb502ee76b1cb0e6751b4083a6e5fbac0bb9c0575da77ba8160903f8ced3
AI access managementAndroid sideloadingCVE-2026-20131CVE-2026-3564Cisco FMCConnectWiseDDoSDSPMInterlockIoT botnetsScreenConnectSemgrepcloud securitycode securitycyber extortiondata protectionlaw enforcementransomwareremote accessscam preventionstreaming fraudzero-day

What happened

Multiple high‑impact security stories: A critical zero‑day in Cisco Secure Firewall Management Center (CVE-2026-20131) was actively exploited by the Interlock ransomware gang beginning Jan 26, 2026—36 days before Cisco’s public disclosure and patch, according to Amazon’s MadPot honeypot telemetry. Separately, ConnectWise patched a critical ScreenConnect flaw (CVE-2026-3564) that allowed remote forging of authentication via ASP.NET machine keys, enabling session hijacking. Law enforcement disrupted four large IoT botnets tied to record DDoS attacks (up to ~30 Tbps). Other notable items: Googleʼ

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
300edb502ee76b1cb0e6751b4083a6e5fbac0bb9c0575da77ba8160903f8ced3
Enrichment time
2026-03-20T14:51:53Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.