AWS Warns Hackers Have Abused Cisco Firewall Zero-Day Since January

AWS Warns Hackers Have Abused Cisco Firewall Zero-Day Since January

By Phil Muncaster
Publication Date: 2026-03-19 09:50:00

A prolific ransomware group has been exploiting a zero-day vulnerability in a Cisco firewall product since January, according to a new analysis from AWS.

AWS CISO, CJ Moses, warned yesterday that the Interlock operation had been using CVE-2026-20131 in attacks since January 26.

CVE-2026-20131 is a remote code execution (RCE) flaw in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software.

Given a maximum CVSS score of 10, it could “allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device,” according to Cisco.

Read more on Interlock: Interlock Ransomware Targets US Healthcare, IT and Government Sectors.

Thanks to a “misconfigured infrastructure server,” the AWS security team was able to gain rare and full visibility in Interlock’s operational toolkit, Moses said.

Following initial access via zero-day exploitation, the group used a PowerShell script to collect details on victims’…