Cisco Secure Firewall Management Center Insecure Java Deserialization RCE (CVE-2026-20131) — Interlock Ransomware Zero-Day Exploitation

Cisco Secure Firewall Management Center Insecure Java (TL-2026-0260), also tracked as cisco-sa-fmc-rce-NKhnULJh, is a critical-severity software vulnerability scored CVSS 10, first published 2026-03-21. It is attributed to Interlock Ransomware Group (Russia) with high confidence, affects Cisco Secure Firewall Management Center (FMC) Software, references 1 CVE (CVE-2026-20131), maps to 25 MITRE ATT&CK techniques (T1003, T1005, T1014), and is covered by 9 detection rules and 20 indicators of compromise.

Key facts for TL-2026-0260

Threat ID
TL-2026-0260
Also known as
cisco-sa-fmc-rce-NKhnULJh, CSCwt14636
Severity
CRITICAL
CVSS
10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-03-21
Last reviewed
2026-03-21
Attribution
Interlock Ransomware Group
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
government, healthcare, education, manufacturing, financial, critical-infrastructure, enterprise
Target regions
North America, Europe, Global
Detection rules
9
Indicators of compromise
20

Malware and tooling in Cisco Secure Firewall Management Center Insecure Java

Malware and tooling: Interlock Ransomware, Slopoly, Certify, ConnectWise ScreenConnect, Custom Java RAT providing redundant C2 communication channel, Custom JavaScript RAT with interactive shell, file transfer, SOCKS5 proxy, self-update and self-delete capabilities, Volatility Framework, ysoserial

Critical unauthenticated remote code execution vulnerability in Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) caused by insecure deserialization of user-supplied Java byte streams (CWE-502). CVSS 10.0. Actively exploited as a zero-day by the Interlock ransomware group since January 26, 2026 — 36 days before Cisco's March 4 disclosure. CISA added to KEV catalog March 19, 2026 with ransomware campaign flag.

How Cisco Secure Firewall Management Center Insecure Java works

CVE-2026-20131 is a maximum-severity (CVSS 10.0) vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management. The flaw resides in the application's handling of serialized Java objects — the management interface accepts and deserializes Java byte streams from untrusted sources without implementing proper input validation, type checking, or object filtering.

An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted serialized Java object (identified by magic bytes 0xAC ED 00 05) to the web-based management interface. The application deserializes this data back into objects without validating the source or content, instantiating classes defined in the stream. This allows attackers to construct malicious object graphs — gadget chains — leveraging existing classpath libraries (similar to ysoserial-generated payloads) to achieve arbitrary Java code execution with root privileges on the affected device.

The vulnerability is tracked as Cisco Bug ID CSCwt14636 and advisory cisco-sa-fmc-rce-NKhnULJh. No workarounds are available; patching is the only remediation.

Amazon threat intelligence teams, using their MadPot honeypot system, discovered that the Interlock ransomware group began exploiting CVE-2026-20131 as a zero-day on January 26, 2026 — a full 36 days before Cisco publicly disclosed and patched the vulnerability on March 4, 2026. An operational security failure by the Interlock group exposed a misconfigured infrastructure server, revealing their complete cybercrime toolkit organized by target victim.

The observed attack chain proceeds as follows: (1) Initial access via crafted HTTP requests containing serialized Java objects targeting a specific path on the FMC management interface; (2) The request body contains Java code execution attempts with two embedded URLs — one delivering configuration data supporting the exploit and another designed to confirm successful exploitation by causing the vulnerable target to perform an HTTP PUT request; (3) An ELF binary payload is fetched from a remote server; (4) A persistent memory-resident backdoor is installed — a Java class file that, when loaded by the JVM, intercepts HTTP requests without writing files to disk; (5) Post-exploitation tooling is deployed including PowerShell reconnaissance scripts, custom JavaScript and Java RATs with SOCKS5 proxy capability, and ConnectWise ScreenConnect for persistent remote access.

Interlock's post-exploitation toolkit includes: PowerShell scripts for Windows environment enumeration (OS details, services, installed software, Hyper-V inventory, browser artifacts from Chrome/Edge/Firefox/IE/360, network connections, RDP logs); custom JavaScript and Java remote access trojans featuring interactive shell access, bidirectional file transfer, SOCKS5 proxy capability, and self-update/self-delete mechanisms; Bash scripts configuring compromised Linux servers as HTTP reverse proxies using fail2ban and HAProxy on port 80; the Volatility Framework for memory forensics and credential extraction; and the Certify tool for Active Directory Certificate Services exploitation.

FMC sits at the center of firewall management operations — a compromised FMC becomes an attacker staging point for broader intrusion, credential harvesting, configuration tampering, and ransomware deployment across the entire managed firewall environment. The Interlock group, active since September 2024, primarily targets education, healthcare, industrial, and government sectors with disruption-driven ransom demands. Notable prior victims include DaVita, Kettering Health, and Texas Tech University. Operational analysis indicates the group operates in the UTC+3 timezone.

MITRE ATT&CK techniques used in TL-2026-0260

credential-access

T1003 OS Credential Dumping; T1649 Steal or Forge Authentication Certificates

collection

T1005 Data from Local System

defense-evasion

T1014 Rootkit; T1027 Obfuscated Files or Information; T1070 Indicator Removal

discovery

T1016 System Network Configuration Discovery; T1018 Remote System Discovery; T1046 Network Service Discovery; T1082 System Information Discovery; T1518 Software Discovery

lateral-movement

T1021 Remote Services

exfiltration

T1041 Exfiltration Over C2 Channel

execution

T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution

privilege-escalation

T1068 Exploitation for Privilege Escalation

command-and-control

T1071 Application Layer Protocol; T1090 Proxy; T1105 Ingress Tool Transfer; T1219 Remote Access Tools

persistence

T1133 External Remote Services; T1505 Server Software Component

initial-access

T1190 Exploit Public-Facing Application

impact

T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery

Affected products and versions in Cisco Secure Firewall Management Center Insecure Java

  • Cisco — Secure Firewall Management Center (FMC) Software
    Vulnerable versions: 6.4.0.13; 6.4.0.14; 6.4.0.15; 6.4.0.16; 6.4.0.17; 6.4.0.18; 7.0.0; 7.0.1; 7.0.2; 7.0.3
    Fixed in: 7.0.9; 7.2.11; 7.4.6; 7.6.5; 7.7.12; 10.0.1
  • Cisco — Security Cloud Control (SCC) Firewall Management
    Vulnerable versions: All versions prior to fix
    Fixed in: Patched via cloud update

Remediation for Cisco Secure Firewall Management Center Insecure Java

Patches

  • Cisco FMC 7.0.9 — fixes versions 6.4.0.13 through 7.0.8.1
  • Cisco FMC 7.2.11 — fixes versions 7.1.0 through 7.2.10.2
  • Cisco FMC 7.4.6 — fixes versions 7.3.0 through 7.4.5
  • Cisco FMC 7.6.5 — fixes versions 7.6.0 through 7.6.4
  • Cisco FMC 7.7.12 — fixes versions 7.7.0 through 7.7.11
  • Cisco FMC 10.0.1 — fixes version 10.0.0

Immediate actions

  • Apply Cisco FMC patches immediately — upgrade to fixed versions (7.0.9, 7.2.11, 7.4.6, 7.6.5, 7.7.12, or 10.0.1)
  • Restrict FMC management interface access to trusted out-of-band management networks only
  • Block public internet access to FMC web management interface at network perimeter
  • Hunt for indicators of compromise: unexpected outbound HTTP PUT requests from FMC, unauthorized ScreenConnect installations, suspicious PowerShell activity, memory-resident threats
  • Review FMC audit logs for unauthorized configuration changes or account modifications

Workarounds

  • No vendor workarounds available — patching is the only remediation
  • Restrict management interface to trusted networks as risk reduction measure

Longer-term hardening

  • Implement network segmentation isolating firewall management plane from general network traffic
  • Deploy EDR with behavioral detection on all management infrastructure hosts
  • Establish continuous vulnerability management for network security appliance management interfaces
  • Implement application allowlisting on management servers to prevent unauthorized binary execution
  • Monitor for Java deserialization attack patterns (magic bytes 0xAC ED 00 05) at WAF/IDS layer

CVEs associated with Cisco Secure Firewall Management Center Insecure Java

CVE-2026-20131

Weaknesses (CWE) in Cisco Secure Firewall Management Center Insecure Java

CWE-502

Timeline of Cisco Secure Firewall Management Center Insecure Java

  • Interlock ransomware group first observed active in the wild, targeting education, healthcare, industrial, and government sectors
  • Interlock ransomware group begins exploiting CVE-2026-20131 as a zero-day against Cisco FMC targets, 36 days before public disclosure (discovered by Amazon MadPot honeypot)
  • Cisco publicly discloses CVE-2026-20131 and releases software updates addressing the vulnerability (Advisory cisco-sa-fmc-rce-NKhnULJh v1.0)
  • Qualys releases QID 317770 for detecting vulnerable Cisco FMC instances
  • Cisco updates advisory to v1.1, confirming reports of active exploitation in the wild
  • Amazon threat intelligence publishes detailed analysis of Interlock campaign, revealing zero-day exploitation timeline and full attack toolkit recovered from misconfigured infrastructure server
  • CISA adds CVE-2026-20131 to Known Exploited Vulnerabilities catalog with ransomware campaign flag; federal agencies ordered to remediate by March 22, 2026
  • CISA BOD 22-01 remediation deadline for US federal civilian agencies
  • As of 2026-05-29, CVE-2026-20131 (CVSS 10.0 Cisco FMC deserialization RCE) is patched but remains in CISA KEV with a ransomware flag and is still actively exploited against unpatched, internet-exposed FMC instances. The Interlock ransomware group is operational—leak-site activity on 2026-05-12, no takedown—keeping this threat active.

Sources cited for Cisco Secure Firewall Management Center Insecure Java

Threats related to Cisco Secure Firewall Management Center Insecure Java

Detection coverage for TL-2026-0260

As of 2026-03-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0260 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats