Cisco Firewall Management Center Has Two CVSS 10.0 Unauthenticated RCEs — Interlock Ransomware Exploited One as Zero-Day

Cisco Firewall Management Center Has Two CVSS 10.0 Unauthenticated RCEs — Interlock Ransomware Exploited One as Zero-Day

By Forkast
Publication Date: 2026-10-08 06:27:00

Analysis

The system managing enterprise firewalls was compromised through unauthenticated root access months before patches were available. Interlock ransomware weaponized the Java deserialization flaw 36 days before Cisco knew about it.

Two critical, unauthenticated remote code execution vulnerabilities in the Cisco Secure Firewall Management Center carry CVSS scores of 10.0. Both allow attackers to gain root access to the system that configures and manages the enterprise security perimeter — the management plane that firewalls depend on to enforce policy.

CVE-2026-20131 is an insecure deserialization flaw in the FMC web-based management interface. It requires no authentication, no user interaction, and has low attack complexity. An attacker sends a crafted serialized Java object to the web interface and executes arbitrary code as root. Cisco’s Keane O’Kelley of the Advanced Security Initiatives Group found it during internal testing. The advisory went live March 4, 2026.

The…