OTX-69de0077cbff2dc8d99b17ff
info
📛 Threat Title
March 2026 CVE Landscape: 31 High-Impact Vulnerabilities Identified, Interlock Ransomware Group Exploits Cisco FMC Zero-Day
Description
In March 2026, 31 high-impact vulnerabilities were identified requiring prioritization for remediation, with 29 receiving Very Critical Risk Scores. Affected vendors included Cisco, Microsoft, Google, ConnectWise, and others, with Microsoft and Apple accounting for approximately 32% of vulnerabilities. Notably, the Interlock Ransomware Group exploited CVE-2026-20131, a zero-day deserialization vulnerability in Cisco Secure Firewall Management Center, as early as January 2026 to compromise enterprise networks. The group deployed custom remote access trojans and facilitated ransomware operations through crafted HTTP requests executing arbitrary Java code as root. Additional campaigns involved the DarkSword iOS exploit kit delivering GHOSTKNIFE, GHOSTSABER, and GHOSTBLADE payloads, and the Coruna exploit kit deploying PlasmaLoader malware. Nine vulnerabilities enabled remote code execution across multiple platforms. One vulnerability dated back nine years, emphasizing continued exploitation of legacy unpatched Pulse contains 26 indicator(s) (IOCs). View on OTX to inspect.
Indicators of Compromise (26)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
cve
CVE-2026-3055
IOC database
- Type
- cve
- Value
CVE-2026-3055- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Citrix NetScaler Out-of-Bounds Read Vulnerability
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
cve
CVE-2025-53521
IOC database
- Type
- cve
- Value
CVE-2025-53521- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
- Description
- F5 BIG-IP Stack-Based Buffer Overflow Vulnerability
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
cve
CVE-2026-33634
IOC database
- Type
- cve
- Value
CVE-2026-33634- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Aquasecurity Trivy Embedded Malicious Code Vulnerability
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
cve
CVE-2026-33017
IOC database
- Type
- cve
- Value
CVE-2026-33017- First seen
- Last seen
- Attached to this threat
- Appears in
- 5 threats
- Description
- Langflow Code Injection Vulnerability
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
cve
CVE-2025-32432
IOC database
- Type
- cve
- Value
CVE-2025-32432- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Craft CMS Code Injection Vulnerability
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
cve
CVE-2025-54068
IOC database
- Type
- cve
- Value
CVE-2025-54068- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Laravel Livewire Code Injection Vulnerability
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
cve
CVE-2026-20131
IOC database
- Type
- cve
- Value
CVE-2026-20131- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
- Description
- Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
cve
CVE-2026-20963
IOC database
- Type
- cve
- Value
CVE-2026-20963- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
cve
CVE-2026-3910
IOC database
- Type
- cve
- Value
CVE-2026-3910- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
cve
CVE-2026-3909
IOC database
- Type
- cve
- Value
CVE-2026-3909- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Google Skia Out-of-Bounds Write Vulnerability
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
cve
CVE-2025-68613
IOC database
- Type
- cve
- Value
CVE-2025-68613- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- n8n Improper Control of Dynamically-Managed Code Resources Vulnerability
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
cve
CVE-2025-26399
IOC database
- Type
- cve
- Value
CVE-2025-26399- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
- Description
- SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
cve
CVE-2017-7921
IOC database
- Type
- cve
- Value
CVE-2017-7921- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Hikvision Multiple Products Improper Authentication Vulnerability
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
cve
CVE-2021-30952
IOC database
- Type
- cve
- Value
CVE-2021-30952- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Apple Multiple Products Integer Overflow or Wraparound Vulnerability
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
cve
CVE-2023-41974
IOC database
- Type
- cve
- Value
CVE-2023-41974- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Apple iOS and iPadOS Use-After-Free Vulnerability
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
cve
CVE-2026-21385
IOC database
- Type
- cve
- Value
CVE-2026-21385- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Qualcomm Multiple Chipsets Memory Corruption Vulnerability
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
cve
CVE-2026-27483
IOC database
- Type
- cve
- Value
CVE-2026-27483- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
cve
CVE-2026-27944
IOC database
- Type
- cve
- Value
CVE-2026-27944- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
cve
CVE-2026-25187
IOC database
- Type
- cve
- Value
CVE-2026-25187- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
cve
CVE-2026-26127
IOC database
- Type
- cve
- Value
CVE-2026-26127- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
cve
CVE-2026-21262
IOC database
- Type
- cve
- Value
CVE-2026-21262- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
cve
CVE-2026-3564
IOC database
- Type
- cve
- Value
CVE-2026-3564- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
6c8efbcef3af80a574cb2aa2224c145bb2e37c2f3d3f091571708288ceb22d5f
VT 44 / 74
IOC database
- Type
- hash_sha256
- Value
6c8efbcef3af80a574cb2aa2224c145bb2e37c2f3d3f091571708288ceb22d5f- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 44 of 74 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Trojan/Win.Agent.C5858422 |
| alibabacloud | malicious | Trojan:Win/BadJoke.LD |
| ALYac | malicious | Trojan.Ransom.ScreenLocker |
| Antiy-AVL | malicious | Trojan/Win32.Screenlock |
| APEX | malicious | Malicious |
| Arcabit | malicious | Trojan.BadJoke.IZ |
| Avast | malicious | Win64:MalwareX-gen [Misc] |
| AVG | malicious | Win64:MalwareX-gen [Misc] |
| Avira | malicious | TR/W64.Agent |
| BitDefender | malicious | Trojan.BadJoke.IZ |
| CTX | malicious | exe.trojan.badjoke |
| Cynet | malicious | Malicious (score: 99) |
| Elastic | malicious | malicious (high confidence) |
| Emsisoft | malicious | Trojan.BadJoke.IZ (B) |
| ESET-NOD32 | malicious | Win64/BadJoke.LX trojan |
| F-Secure | malicious | Trojan.TR/W64.Agent |
| Fortinet | malicious | Riskware/Screenlocker |
| GData | malicious | Trojan.BadJoke.IZ |
| malicious | Detected |
|
| K7AntiVirus | malicious | Riskware ( 00584baa1 ) |
| K7GW | malicious | Riskware ( 00584baa1 ) |
| Kaspersky | malicious | Trojan.Win64.Agent.smftnu |
| Lionic | malicious | Trojan.Win32.BadJoke.4!c |
| Malwarebytes | malicious | Generic.Malware/Suspicious |
| McAfeeD | malicious | ti!6C8EFBCEF3AF |
| Microsoft | malicious | Trojan:Win32/ScreenLock!MTB |
| MicroWorld-eScan | malicious | Trojan.BadJoke.IZ |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/PhxBzA.A |
| Rising | malicious | Trojan.ScreenLock!8.1CA53 (CLOUD) |
| Sangfor | malicious | Trojan.Win64.Badjoke.Vyrh |
| Skyhigh | malicious | BehavesLike.Win64.Infected.mh |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Trojan.Gen.MBT |
| Tencent | malicious | Malware.Win32.Gencirc.10c46757 |
| TrellixENS | malicious | Artemis!12D399E6966D |
| TrendMicro | malicious | Trojan.Win32.SCREENLOCK.USBLCT26 |
| TrendMicro-HouseCall | malicious | Trojan.Win32.SCREENLOCK.USBLCT26 |
| Varist | malicious | W64/ABTrojan.QTSE-6757 |
| VBA32 | malicious | Trojan.Win64.Agent |
| VIPRE | malicious | Trojan.BadJoke.IZ |
| VirIT | malicious | Trojan.Win64.Genus.JJG |
| ViRobot | malicious | Trojan.Win.C.Screenlock.25088 |
| Xcitium | malicious | Malware@#h8e4ms93g0mj |
Details From VirusTotal
Basic Properties
| MD5 | 12d399e6966db58f6d189d606ac34cc8 |
| SHA-1 | 17986b6595fe960fe8e9757d3069d5daabd628ef |
| SHA-256 | 6c8efbcef3af80a574cb2aa2224c145bb2e37c2f3d3f091571708288ceb22d5f |
| VHash | 0240b75d7555151c0d1d1bzc19hz11zffz |
| SSDEEP | 384:5J/++vXbOLh+S8DkuOa2+QGw/ECJYMEKTH07YjG3CW:5EO8+SKkuOpjEC2MLTUnSW |
| TLSH | T197B2391EF32258DDC396C078D1DB5771E1B5BC1241A6AB2A271CE138AF26DE6DE3E101 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows |
| File size | 24.5 KB |
History
| Creation date | 2024-11-11 15:52 UTC |
| First seen on VirusTotal | 2026-02-18 14:07 UTC |
| Last submission | 2026-03-24 11:43 UTC |
| Last analysis | 2026-07-23 11:25 UTC |
| Last modified on VirusTotal | 2026-07-23 13:28 UTC |
Known Names
CYOywFTkk6c8efbcef3af80a574cb2aa2224c145bb2e37c2f3d3f091571708288ceb22d5f.exe_6c8efbcef3af80a574cb2aa2224c145bb2e37c2f3d3f091571708288ceb22d5f.exeGcFeu5yd1tbc.exe2026-02-19_12d399e6966db58f6d189d606ac34cc8_cobalt-strike_conti
hash_md5
12d399e6966db58f6d189d606ac34cc8
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/12d399e6966db58f6d189d606ac34cc8
IOC database
- Type
- hash_md5
- Value
12d399e6966db58f6d189d606ac34cc8- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/12d399e6966db58f6d189d606ac34cc8
hash_sha1
17986b6595fe960fe8e9757d3069d5daabd628ef
VT: VT base fetch failed: HTTPError: 500 Server Error: Internal Server Error for url: https://www.virustotal.com/api/v3/files/17986b6595fe960fe8e9757d3069d5daabd628ef
IOC database
- Type
- hash_sha1
- Value
17986b6595fe960fe8e9757d3069d5daabd628ef- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 500 Server Error: Internal Server Error for url: https://www.virustotal.com/api/v3/files/17986b6595fe960fe8e9757d3069d5daabd628ef
cve
CVE-2026-33032
IOC database
- Type
- cve
- Value
CVE-2026-33032- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
-
OTX pulse
AlienVaulkt OTX
In March 2026, 31 high-impact vulnerabilities were identified requiring prioritization for remediation, with 29 receiving Very Critical Risk Scores. Affected vendors included Cisco, Microsoft, Google, ConnectWise, and others, with Microsoft and Apple accounting for approximately 32% of vulnerabilities. Notably, the Interlock Ransomware Group exploited CVE-2026-20131, a zero-day deserialization vulnerability in Cisco Secure Firewall Management Center, as early as January 2026 to compromise enterp
- reference AlienVaulkt OTX
Remediations (10)
-
web:cybernoz.com
According to Amazon Threat Intelligence, Interlock Ransomware Group exploited CVE - 2026 -20131 as a zero -day vulnerability beginning January 26, 2026 , indicating active exploitation prior to its public disclosure and enabling early compromise of enterprise networks.
-
web:cyberpress.org
In March 2026 , researchers at Insikt Group identified 31 high-impact cybersecurity vulnerabilities requiring urgent remediation. According to the threat intelligence data, 29 of these flaws received a Very Critical risk score.
-
web:cybersecuritynews.com
The Interlock Ransomware Group's exploitation of CVE - 2026 -20131 began on January 26, 2026 — weeks before Cisco published its security advisory on March 4. This means the group had been operating inside enterprise networks using a vulnerability that defenders had no official patch or public knowledge of at the time.
-
web:gbhackers.com
31 high-impact vulnerabilities were actively exploited in March 2026 , with a Cisco firewall zero -day abused by the Interlock ransomware group .
-
web:getsecure.ai
Notably, the Interlock Ransomware Group was found to be exploiting a zero -day vulnerability in Cisco's Firepower Management Center ( FMC ) 1. The presence of zero -day activity, particularly targeting Microsoft products, underscores the urgent need for prompt patching and vulnerability assessment.
-
web:securitricks.com
Description In March 2026 , 31 high-impact vulnerabilities were identified requiring prioritization for remediation, with 29 receiving Very Critical Risk Scores. Affected vendors included Cisco , Microsoft, Google, ConnectWise, and others, with Microsoft and Apple accounting for approximately 32% of vulnerabilities . Notably, the Interlock Ransomware Group exploited CVE - 2026 -20131, a zero -day ...
-
web:thehackernews.com
Interlock ransomware is actively exploiting CVE - 2026 -20131 (CVSS 10.0) in Cisco FMC , enabling unauthenticated remote code execution as root.
-
web:www.allsecuritynews.com
In March 2026 , Insikt Group identified 31 high-impact vulnerabilities that should be prioritized for remediation, with 29 having a Very Critical Recorded Future Risk Score. The Interlock Ransomware Group exploited a Cisco FMC zero -day vulnerability.
-
web:www.enigma-global.com
In March 2026 , 31 high-impact vulnerabilities were identified as actively exploited in the wild, with the most critical being CVE - 2026 -20131, a maximum-severity (CVSS 10.0) unauthenticated remote code execution vulnerability in Cisco Secure Firewall Management Center ( FMC ) Software.
-
web:www.recordedfuture.com
March 2026 saw a 139% increase in high-impact vulnerabilities , with Recorded Future's Insikt Group ® identifying 31 vulnerabilities requiring immediate remediation, up from 13 in February 2026 .
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.