Wednesday , August 5 2026
Secure Firewall
FILE PHOTO: The logo of U.S. networks giant Cisco Systems is seen in front of their headquarters in Issy-les-Moulineaux, near Paris, France August 6, 2022. REUTERS/Sarah Meyssonnier/File Photo

CISA warns feds to patch max-severity Cisco flaw by Sunday

Cybersecurity and Infrastructure Security Agency (CISA) ordered federal agencies to fix a serious flaw, CVE-2026-20131, in Cisco Secure Firewall Management Center (FMC) by Sunday, March 22.

Cisco released a security bulletin about the flaw on March 4. They told system managers to install the security updates quickly and said there are no fixes to work around it.

Brazilian health surveillance platform breach exposes 100K+ sensitive documents

Cybersecurity Researcher Jeremiah Fowler uncovered and reported to Express VPN a publicly exposed database that was neither password-protected nor encrypted....
Read More
Brazilian health surveillance platform breach exposes 100K+ sensitive documents

Thousands of data centers are at risk of compromise due to a 22-year-old flaw

Thousands of data centers are in danger because of a 22-year-old problem in Baseboard Management Controller (BMC) processors, says the...
Read More
Thousands of data centers are at risk of compromise due to a 22-year-old flaw

Bangladesh Launches (CIRS) and National ICT & Cyber Security Rating System (NRS)

In an important move to boost the country's cybersecurity, Bangladesh started the Cyber Incident Reporting System (CIRS) and the National...
Read More
Bangladesh Launches (CIRS) and National ICT & Cyber Security Rating System (NRS)

CVE-2026-18574
Check Point Authentication Bypass Hits Management Server

Check Point fixed a flaw that allowed bypassing authentication on its Security Management and Multi-Domain Security Management servers. This issue...
Read More
CVE-2026-18574  Check Point Authentication Bypass Hits Management Server

TP-Link RCE and SonicWall Zero-Click Flaws Enable Complete Device Compromise

TP-Link has shared a security warning about a serious problem with its TL-WR940N V6 wireless router. This problem, known as...
Read More
TP-Link RCE and SonicWall Zero-Click Flaws Enable Complete Device Compromise

ExfilSquad releases info of over 100,000 UK police officers, staff

A cyberattack on the U.K.'s Police National Legal Database (PNLD) has put the contact information of over 100,000 police officers...
Read More
ExfilSquad releases info of over 100,000 UK police officers, staff

CISA alerts to cyberattacks affecting U.S. water utilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns of a big rise in attacks on internet-connected programmable logic controllers...
Read More
CISA alerts to cyberattacks affecting U.S. water utilities

“CyberStrike” AI-Driven Security Platform for Automated Testing

A new open-source project named CyberStrike aims to be the first AI tool made for offensive security. It can turn...
Read More
“CyberStrike” AI-Driven Security Platform for Automated Testing

AIDCQ Propose to invest $2 billion in AI data center in Bangladesh

Many countries are now showing interest to invest in the data center industry in Banglades especially in AI data centers....
Read More
AIDCQ Propose to invest $2 billion in AI data center in Bangladesh

NVIDIA BlueField Flaw Enables Code Execution Attacks

NVIDIA has revealed a big flaw with its BlueField DPUs and ConnectX networking systems. This issue could let attackers run...
Read More
NVIDIA BlueField Flaw Enables Code Execution Attacks

The Cisco Secure Firewall Management Center (FMC) is a main control system for important Cisco network security tools, like firewalls, application control, intrusion prevention, URL filtering, and malware protection.

“A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device,” Cisco says in the advisory.

The flaw comes from unsafe deserialization of a Java byte stream provided by the user. It can be exploited by sending a specially made Java object to the web management interface of a device that is affected.

On March 18, the vendor updated its notice to say that CVE-2026-20131 is being actively used to attack systems. Researchers at Amazon found that hackers are using this weakness in their attacks, and that the Interlock ransomware group has been taking advantage of it as a zero-day since late January.

Amazon stated that the ransomware threat actor exploited CVE-2026-20131 more than a month before the vendor published the patch.

Interlock ransomware has claimed many well-known targets since it started in late 2024. Some of these include DaVita, Kettering Health, the Texas Tech University System, and the city of Saint Paul in Minnesota.

The attacker is using the ClickFix method to get in. They are also using special remote access tools and malware like NodeSnake and Slopoly.

CISA has added CVE-2026-20131 to its Known Exploited Vulnerabilities (KEV) catalog, marking it as “known to be used in ransomware campaigns.”

Given the severity of CVE-2026-20131 and its active exploitation status since late January 2026, CISA gave Federal Civilian Executive Branch (FCEB) agencies only until this Sunday to apply the security updates or stop using the product.

CISA’s deadline matters to all groups under Binding Operational Directive (BOD) 22-01, but private companies, state and local governments, and non-FCEB organizations should still think about it and take action.

Check Also

Cursor

Cursor, SonicWall, SharePoint 0-day exploited to the wild

A serious security flaw in Cursor, a popular AI code editor used by more than …