s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

OTX-69de0077cbff2dc8d99b17ff info

📛 Threat Title

March 2026 CVE Landscape: 31 High-Impact Vulnerabilities Identified, Interlock Ransomware Group Exploits Cisco FMC Zero-Day

Category: Interlock Ransomware Group Published: Source updated: First seen: Last updated: Source: AlienVaulkt OTX

Description

In March 2026, 31 high-impact vulnerabilities were identified requiring prioritization for remediation, with 29 receiving Very Critical Risk Scores. Affected vendors included Cisco, Microsoft, Google, ConnectWise, and others, with Microsoft and Apple accounting for approximately 32% of vulnerabilities. Notably, the Interlock Ransomware Group exploited CVE-2026-20131, a zero-day deserialization vulnerability in Cisco Secure Firewall Management Center, as early as January 2026 to compromise enterprise networks. The group deployed custom remote access trojans and facilitated ransomware operations through crafted HTTP requests executing arbitrary Java code as root. Additional campaigns involved the DarkSword iOS exploit kit delivering GHOSTKNIFE, GHOSTSABER, and GHOSTBLADE payloads, and the Coruna exploit kit deploying PlasmaLoader malware. Nine vulnerabilities enabled remote code execution across multiple platforms. One vulnerability dated back nine years, emphasizing continued exploitation of legacy unpatched Pulse contains 26 indicator(s) (IOCs). View on OTX to inspect.

Indicators of Compromise (26)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

cve CVE-2026-3055

IOC database

Type
cve
Value
CVE-2026-3055
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Citrix NetScaler Out-of-Bounds Read Vulnerability

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

cve CVE-2025-53521

IOC database

Type
cve
Value
CVE-2025-53521
First seen
Last seen
Attached to this threat
Appears in
3 threats
Description
F5 BIG-IP Stack-Based Buffer Overflow Vulnerability

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

cve CVE-2026-33634

IOC database

Type
cve
Value
CVE-2026-33634
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Aquasecurity Trivy Embedded Malicious Code Vulnerability

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

cve CVE-2026-33017

IOC database

Type
cve
Value
CVE-2026-33017
First seen
Last seen
Attached to this threat
Appears in
5 threats
Description
Langflow Code Injection Vulnerability

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

cve CVE-2025-32432

IOC database

Type
cve
Value
CVE-2025-32432
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Craft CMS Code Injection Vulnerability

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

cve CVE-2025-54068

IOC database

Type
cve
Value
CVE-2025-54068
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Laravel Livewire Code Injection Vulnerability

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

cve CVE-2026-20131

IOC database

Type
cve
Value
CVE-2026-20131
First seen
Last seen
Attached to this threat
Appears in
3 threats
Description
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

cve CVE-2026-20963

IOC database

Type
cve
Value
CVE-2026-20963
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

cve CVE-2026-3910

IOC database

Type
cve
Value
CVE-2026-3910
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

cve CVE-2026-3909

IOC database

Type
cve
Value
CVE-2026-3909
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Google Skia Out-of-Bounds Write Vulnerability

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

cve CVE-2025-68613

IOC database

Type
cve
Value
CVE-2025-68613
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
n8n Improper Control of Dynamically-Managed Code Resources Vulnerability

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

cve CVE-2025-26399

IOC database

Type
cve
Value
CVE-2025-26399
First seen
Last seen
Attached to this threat
Appears in
3 threats
Description
SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

cve CVE-2017-7921

IOC database

Type
cve
Value
CVE-2017-7921
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Hikvision Multiple Products Improper Authentication Vulnerability

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

cve CVE-2021-30952

IOC database

Type
cve
Value
CVE-2021-30952
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Apple Multiple Products Integer Overflow or Wraparound Vulnerability

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

cve CVE-2023-41974

IOC database

Type
cve
Value
CVE-2023-41974
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Apple iOS and iPadOS Use-After-Free Vulnerability

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

cve CVE-2026-21385

IOC database

Type
cve
Value
CVE-2026-21385
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Qualcomm Multiple Chipsets Memory Corruption Vulnerability

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

cve CVE-2026-27483

IOC database

Type
cve
Value
CVE-2026-27483
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

cve CVE-2026-27944

IOC database

Type
cve
Value
CVE-2026-27944
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

cve CVE-2026-25187

IOC database

Type
cve
Value
CVE-2026-25187
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

cve CVE-2026-26127

IOC database

Type
cve
Value
CVE-2026-26127
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

cve CVE-2026-21262

IOC database

Type
cve
Value
CVE-2026-21262
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

cve CVE-2026-3564

IOC database

Type
cve
Value
CVE-2026-3564
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 6c8efbcef3af80a574cb2aa2224c145bb2e37c2f3d3f091571708288ceb22d5f VT 44 / 74

IOC database

Type
hash_sha256
Value
6c8efbcef3af80a574cb2aa2224c145bb2e37c2f3d3f091571708288ceb22d5f
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 44 of 74 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Win.Agent.C5858422
alibabacloud malicious Trojan:Win/BadJoke.LD
ALYac malicious Trojan.Ransom.ScreenLocker
Antiy-AVL malicious Trojan/Win32.Screenlock
APEX malicious Malicious
Arcabit malicious Trojan.BadJoke.IZ
Avast malicious Win64:MalwareX-gen [Misc]
AVG malicious Win64:MalwareX-gen [Misc]
Avira malicious TR/W64.Agent
BitDefender malicious Trojan.BadJoke.IZ
CTX malicious exe.trojan.badjoke
Cynet malicious Malicious (score: 99)
Elastic malicious malicious (high confidence)
Emsisoft malicious Trojan.BadJoke.IZ (B)
ESET-NOD32 malicious Win64/BadJoke.LX trojan
F-Secure malicious Trojan.TR/W64.Agent
Fortinet malicious Riskware/Screenlocker
GData malicious Trojan.BadJoke.IZ
Google malicious Detected
K7AntiVirus malicious Riskware ( 00584baa1 )
K7GW malicious Riskware ( 00584baa1 )
Kaspersky malicious Trojan.Win64.Agent.smftnu
Lionic malicious Trojan.Win32.BadJoke.4!c
Malwarebytes malicious Generic.Malware/Suspicious
McAfeeD malicious ti!6C8EFBCEF3AF
Microsoft malicious Trojan:Win32/ScreenLock!MTB
MicroWorld-eScan malicious Trojan.BadJoke.IZ
Paloalto malicious generic.ml
Panda malicious Trj/PhxBzA.A
Rising malicious Trojan.ScreenLock!8.1CA53 (CLOUD)
Sangfor malicious Trojan.Win64.Badjoke.Vyrh
Skyhigh malicious BehavesLike.Win64.Infected.mh
Sophos malicious Mal/Generic-S
Symantec malicious Trojan.Gen.MBT
Tencent malicious Malware.Win32.Gencirc.10c46757
TrellixENS malicious Artemis!12D399E6966D
TrendMicro malicious Trojan.Win32.SCREENLOCK.USBLCT26
TrendMicro-HouseCall malicious Trojan.Win32.SCREENLOCK.USBLCT26
Varist malicious W64/ABTrojan.QTSE-6757
VBA32 malicious Trojan.Win64.Agent
VIPRE malicious Trojan.BadJoke.IZ
VirIT malicious Trojan.Win64.Genus.JJG
ViRobot malicious Trojan.Win.C.Screenlock.25088
Xcitium malicious Malware@#h8e4ms93g0mj

Details From VirusTotal

Basic Properties
MD512d399e6966db58f6d189d606ac34cc8
SHA-117986b6595fe960fe8e9757d3069d5daabd628ef
SHA-2566c8efbcef3af80a574cb2aa2224c145bb2e37c2f3d3f091571708288ceb22d5f
VHash0240b75d7555151c0d1d1bzc19hz11zffz
SSDEEP384:5J/++vXbOLh+S8DkuOa2+QGw/ECJYMEKTH07YjG3CW:5EO8+SKkuOpjEC2MLTUnSW
TLSHT197B2391EF32258DDC396C078D1DB5771E1B5BC1241A6AB2A271CE138AF26DE6DE3E101
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows
File size24.5 KB
History
Creation date2024-11-11 15:52 UTC
First seen on VirusTotal2026-02-18 14:07 UTC
Last submission2026-03-24 11:43 UTC
Last analysis2026-07-23 11:25 UTC
Last modified on VirusTotal2026-07-23 13:28 UTC
Known Names
  • CYOywFTkk
  • 6c8efbcef3af80a574cb2aa2224c145bb2e37c2f3d3f091571708288ceb22d5f.exe
  • _6c8efbcef3af80a574cb2aa2224c145bb2e37c2f3d3f091571708288ceb22d5f.exe
  • GcFeu5
  • yd1tbc.exe
  • 2026-02-19_12d399e6966db58f6d189d606ac34cc8_cobalt-strike_conti
hash_md5 12d399e6966db58f6d189d606ac34cc8 VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/12d399e6966db58f6d189d606ac34cc8

IOC database

Type
hash_md5
Value
12d399e6966db58f6d189d606ac34cc8
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/12d399e6966db58f6d189d606ac34cc8

hash_sha1 17986b6595fe960fe8e9757d3069d5daabd628ef VT: VT base fetch failed: HTTPError: 500 Server Error: Internal Server Error for url: https://www.virustotal.com/api/v3/files/17986b6595fe960fe8e9757d3069d5daabd628ef

IOC database

Type
hash_sha1
Value
17986b6595fe960fe8e9757d3069d5daabd628ef
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 500 Server Error: Internal Server Error for url: https://www.virustotal.com/api/v3/files/17986b6595fe960fe8e9757d3069d5daabd628ef

cve CVE-2026-33032

IOC database

Type
cve
Value
CVE-2026-33032
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (2)

  • OTX pulse AlienVaulkt OTX

    In March 2026, 31 high-impact vulnerabilities were identified requiring prioritization for remediation, with 29 receiving Very Critical Risk Scores. Affected vendors included Cisco, Microsoft, Google, ConnectWise, and others, with Microsoft and Apple accounting for approximately 32% of vulnerabilities. Notably, the Interlock Ransomware Group exploited CVE-2026-20131, a zero-day deserialization vulnerability in Cisco Secure Firewall Management Center, as early as January 2026 to compromise enterp

  • reference AlienVaulkt OTX

Remediations (10)

  • web:cybernoz.com

    According to Amazon Threat Intelligence, Interlock Ransomware Group exploited CVE - 2026 -20131 as a zero -day vulnerability beginning January 26, 2026 , indicating active exploitation prior to its public disclosure and enabling early compromise of enterprise networks.

  • web:cyberpress.org

    In March 2026 , researchers at Insikt Group identified 31 high-impact cybersecurity vulnerabilities requiring urgent remediation. According to the threat intelligence data, 29 of these flaws received a Very Critical risk score.

  • web:cybersecuritynews.com

    The Interlock Ransomware Group's exploitation of CVE - 2026 -20131 began on January 26, 2026 — weeks before Cisco published its security advisory on March 4. This means the group had been operating inside enterprise networks using a vulnerability that defenders had no official patch or public knowledge of at the time.

  • web:gbhackers.com

    31 high-impact vulnerabilities were actively exploited in March 2026 , with a Cisco firewall zero -day abused by the Interlock ransomware group .

  • web:getsecure.ai

    Notably, the Interlock Ransomware Group was found to be exploiting a zero -day vulnerability in Cisco's Firepower Management Center ( FMC ) 1. The presence of zero -day activity, particularly targeting Microsoft products, underscores the urgent need for prompt patching and vulnerability assessment.

  • web:securitricks.com

    Description In March 2026 , 31 high-impact vulnerabilities were identified requiring prioritization for remediation, with 29 receiving Very Critical Risk Scores. Affected vendors included Cisco , Microsoft, Google, ConnectWise, and others, with Microsoft and Apple accounting for approximately 32% of vulnerabilities . Notably, the Interlock Ransomware Group exploited CVE - 2026 -20131, a zero -day ...

  • web:thehackernews.com

    Interlock ransomware is actively exploiting CVE - 2026 -20131 (CVSS 10.0) in Cisco FMC , enabling unauthenticated remote code execution as root.

  • web:www.allsecuritynews.com

    In March 2026 , Insikt Group identified 31 high-impact vulnerabilities that should be prioritized for remediation, with 29 having a Very Critical Recorded Future Risk Score. The Interlock Ransomware Group exploited a Cisco FMC zero -day vulnerability.

  • web:www.enigma-global.com

    In March 2026 , 31 high-impact vulnerabilities were identified as actively exploited in the wild, with the most critical being CVE - 2026 -20131, a maximum-severity (CVSS 10.0) unauthenticated remote code execution vulnerability in Cisco Secure Firewall Management Center ( FMC ) Software.

  • web:www.recordedfuture.com

    March 2026 saw a 139% increase in high-impact vulnerabilities , with Recorded Future's Insikt Group ® identifying 31 vulnerabilities requiring immediate remediation, up from 13 in February 2026 .

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.