Cisco Firewall Zero-Day Actively Exploited in Ransomware Attacks
Security Bulletin Cisco Firewall Zero-Day Exploitation in Ransomware Campaigns Date: March 2026Severity: CriticalThreat Type: Initial Access / Infrastructure Compromise Executive Summary A recently disclosed set of Cisco firewall and management interface vulnerabilities are now being actively exploited in the wild, including in ransomware campaigns associated with the Interlock group. These vulnerabilities allow unauthenticated attackers to gain control of firewall infrastructure, effectively bypassing traditional security controls and gaining direct access into internal networks. This represents a significant shift in attacker behavior, targeting core network infrastructure rather than endpoints or users. What's Going On Cisco has disclosed multiple critical vulnerabilities affecting firewall management platforms, including Cisco Secure Firewall Management Center (FMC). These vulnerabilities enable attackers to: Execute arbitrary code remotely Bypass authentication mechanisms Obtain root-level access to affected systems In some observed cases, exploitation can occur through crafted HTTP requests sent directly to exposed management interfaces. This means an externally accessible firewall…
