Cisco Secure Firewall Management Center Insecure Java Deserialization RCE (CVE-2026-20131) — Interlock Ransomware Zero-Day Exploitation — Threadlinqs Intelligence
As of 2026-05-30, Cisco Secure Firewall Management Center Insecure Java Deserialization RCE (CVE-2026-20131) — Interlock Ransomware Zero-Day Exploitation is a critical-severity vulnerability threat attributed to Interlock Ransomware Group (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-0260 · Severity: CRITICAL · CVSS: 10 · Status: ACTIVE · Category: VULNERABILITY
Attribution: Interlock Ransomware Group · Russia · FINANCIAL
Critical unauthenticated remote code execution vulnerability in Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) caused by insecure deserialization of user-supplied Java
CVE-2026-20131 is a maximum-severity (CVSS 10.0) vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management. The flaw resides in the application's handling of serialized Java objects — the management interface accepts and deserializes Java byte streams from untrusted sources without implementing proper input validation, type checking, or object filtering.
An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted serialized Java object (identified by magic bytes 0xAC ED 00 05) to the web-based management interface. The application deserializes this data back into objects without validating the source or content, instantiating classes defined in the stream. This allows attackers to construct malicious object graphs — gadget chains — leveraging existing classpath libraries (similar to ysoserial-generated payloads) to achieve arbitrary Java code execution with root privileges on the affected device.
The vulnerability is tracked as Cisco Bug ID CSCwt14636 and advisory cisco-sa-fmc-rce-NKhnULJh. No workarounds are available; patching is the only remediation.
Amazon threat intelligence teams, using their MadPot honeypot system, discovered that the Interlock ransomware group began exploiting CVE-2026-20131 as a zero-day on January 26, 2026 — a full 36 days before Cisco publicly disclosed and patched the vulnerability on March 4, 2026. An operational security failure by the Interlock group exposed a misconfigured infrastructure server, revealing their complete cybercrime toolkit organized by target victim.
The observed attack chain proceeds as follows: (1) Initial access via crafted HTTP requests containing serialized Java objects targeting a specific path on the FMC management interface; (2) The request body contains Java code execution attempts with two embedded URLs — one delivering configuration data supporting the exploit and another designed to confirm successful exploitation by causing the vulnerable target to perform an HTTP PUT request; (3) An ELF binary payload is fetched from a remote server; (4) A persistent memory-resident backdoor is installed — a Java class file that, when loaded by the JVM, intercepts HTTP requests without writing files to disk; (5) Post-exploitation tooling is deployed including PowerShell reconnaissance scripts, custom JavaScript and Java RATs with SOCKS5 proxy capability, and ConnectWise ScreenConnect for persistent remote access.
Interlock's post-exploitation toolkit includes: PowerShell scripts for Windows environment enumeration (OS details, services, installed software, Hyper-V inventory, browser artifacts from Chrome/Edge/Firefox/IE/360, network connections, RDP logs); custom JavaScript and Java remote access trojans featuring interactive shell access, bidirectional file transfer, SOCKS5 proxy capability, and self-update/self-delete mechanisms; Bash scripts configuring compromised Linux servers as HTTP reverse proxies using fail2ban and HAProxy on port 80; the Volatility Framework for memory forensics and credential extraction; and the Certify tool for Active Directory Certificate Services exploitation.
FMC sits at the center of firewall management operations — a compromised FMC becomes an attacker staging point for broader intrusion, credential harvesting, configuration tampering, and ransomware deployment across the entire managed firewall environment. The Interlock group, active since September 2024, primarily targets education, healthcare, industrial, and government sectors with disruption-driven ransom demands. Notable prior victims include DaVita, Kettering Health, and Texas Tech University. Operational analysis indicates the group operates in the UTC+3 timezone.
Target sectors: government, healthcare, education, manufacturing, financial, critical-infrastructure, enterprise
Target regions: North America, Europe, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-20131, T1190, T1203, T1059, T1059, T1059, T1505, T1133, T1068, T1070, T1027