Critical Cisco Flaws Expose Enterprise Security to Threat Actors
A series of critical vulnerabilities in Cisco's infrastructure has exposed a systemic collapse in centralized control. The weaknesses, which include three CVSS 10.0-rated flaws, have been exploited by threat actors to gain access to entire security and connectivity stacks.
The first vulnerability, CVE-2026-20131, was discovered in January 2026 when Interlock ransomware exploited a zero-day in Cisco's Secure Firewall Management Center for 36 days before it was detected. The attackers misconfigured a staging server, exposing their toolkit and allowing researchers to identify the campaign.
The vulnerabilities center on authentication failures in Cisco's centralized management infrastructure. In one case, an attacker could inject an RSA public key into the vmanage-admin authorized_keys file, giving them access to NETCONF and enabling manipulation of the entire SD-WAN fabric.
Cisco Talos has tracked the threat actor UAT-8616 since 2023, which uses software downgrades to chain older exploits for root escalation. CISA issued an Emergency Directive with a 48-hour federal remediation deadline in response to the vulnerabilities.