U.S. CISA adds a flaw in Cisco FMC and Cisco SCC Firewall Management to its Known Exploited Vulnerabilities catalog

2026-03-19T20:51:47Zb7f9c33590231125709083cddf7357765a02667d89bb0813c2d08bd65e75577f
APTCISA KEVCVE-2025-66376CVE-2026-20131CVE-2026-32746CVE-2026-3888Cisco FMCCisco SCCDarkSwordGNU InetutilsInterlock ransomwareIntuitiveTelnetdUbuntu DesktopVienna spy hubXSSZimbradata breachespionageiOS exploit kitphishingprivilege escalationremote code executionsystemdzero-day

What happened

Multiple high‑risk vulnerabilities and active exploitation observed across enterprise and consumer technologies. CISA added a critical Cisco Secure Firewall Management Center / SCC flaw (CVE-2026-20131) to its Known Exploited Vulnerabilities catalog; the Interlock ransomware group exploited this RCE zero‑day in the wild prior to public disclosure. A Russia‑linked APT is actively exploiting a Zimbra XSS (CVE-2025-66376) against Ukrainian targets. Lookout disclosed DarkSword, a powerful iOS exploit kit used by multiple actors including surveillance/nation‑state operators. Researchers reported an

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
b7f9c33590231125709083cddf7357765a02667d89bb0813c2d08bd65e75577f
Enrichment time
2026-03-19T20:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.