CISA: Patch critical Cisco bug by Sunday. Federal agencies must act fast.
Mar 20, 2026 // 18:17 - Tristan Wall


The Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies must address a critical vulnerability, CVE-2026-20131, in Cisco Secure Firewall Management Center (FMC) by Sunday, March 22.

Cisco issued a security announcement on March 4, advising administrators to promptly install the necessary security patches, emphasizing the absence of alternative solutions.

Cisco Secure Firewall Management Center (FMC) provides a centralized platform for managing key Cisco network security components, including firewalls, application control, intrusion prevention systems, URL filtering, and malware protection.

“A security weakness in the Cisco Secure Firewall Management Center (FMC) Software’s web interface could enable an unauthorized remote attacker to execute any Java code as root on a susceptible system,” Cisco explained in the security advisory.

The vulnerability stems from insecure deserialization of Java byte streams provided by a user. Exploitation involves sending a crafted serialized Java object to the web interface of a vulnerable device.

On March 18, Cisco updated its advisory to reflect ongoing exploitation of CVE-2026-20131 in real-world attacks. Independent confirmation from Amazon’s threat intelligence team indicated that attackers are actively using the flaw, with the Interlock ransomware group exploiting it as a zero-day since late January.

Amazon reported that the Interlock ransomware actors were exploiting the CVE-2026-20131 flaw over a month prior to Cisco’s official patch release.

Interlock ransomware has impacted several prominent organizations since its emergence in late 2024, including DaVita, Kettering Health, the Texas Tech University System, and the city of Saint Paul, Minnesota.

The attacker also employs the ClickFix technique for initial system access, alongside custom remote access trojans and malware like NodeSnake and Slopoly.

CISA has added CVE-2026-20131 to its Known Exploited Vulnerabilities (KEV) catalog, designating it as a vulnerability “known to be leveraged in ransomware attacks.”

Given the critical severity of CVE-2026-20131 and its ongoing exploitation since the end of January 2026, CISA has given Federal Civilian Executive Branch (FCEB) agencies until this Sunday to implement the security updates or discontinue use of the affected product.

While CISA’s deadline specifically applies to entities governed by Binding Operational Directive (BOD) 22-01, private sector organizations, state and local governments, and non-FCEB organizations are encouraged to treat it as a recommendation and take appropriate action.

#act  #agencies  #bug  #cisa  #cisco  #critical  #fast.  #federal  #must  #news  #patch  #sunday.   —   News