← Grįžti į visas naujienas

Interlock Ransomware Exploits Cisco FMC Zero-Day for Root Access

The Interlock ransomware group exploited a critical CVSS 10.0 vulnerability in Cisco Firewall Management Center to gain unauthenticated root access, actively exploited in the wild for weeks before public disclosure.

Interlock Ransomware Exploits Cisco FMC Zero-Day for Root Access

The Interlock ransomware group exploited a critical CVSS 10.0 vulnerability in Cisco Firewall Management Center (CVE-2026-20131) to gain unauthenticated root access to enterprise networks. The flaw was actively exploited in the wild for several weeks before public disclosure, giving attackers ample time to move laterally and deploy ransomware payloads across targeted environments.

Cisco issued an emergency patch, but organisations without active vulnerability management programmes remained exposed long after the fix was available.

What this means for your organisation: a zero-day in your firewall management platform is about as bad as it gets for network security. If an attacker can reconfigure your perimeter from the inside, everything behind it is at risk. The weeks-long exposure window before disclosure meant most affected organisations had no chance to act until it was already too late. If you're running Cisco FMC, patch immediately and go back through logs. Any externally accessible management interfaces should be isolated or restricted regardless of this incident.

Šaltinis: The Hacker News

Norite to savo organizacijai?