31 high-impact vulnerabilities were actively exploited in March 2026, with a Cisco firewall zero-day abused by the Interlock ransomware group emerging as one of the most dangerous threats to enterprise networks.
Affected vendors span core enterprise and developer ecosystems, including Cisco, Microsoft, Google, ConnectWise, Langflow, Citrix, Aquasecurity, Nginx UI, Qualcomm, F5, Craft CMS, Laravel, Apple, Synacor, Wing FTP Server, n8n, Omnissa, SolarWinds, Ivanti, Hikvision, Rockwell, and Broadcom.
Microsoft and Apple were hit hardest, together accounting for roughly 32% of the 31 bugs, underscoring the continued targeting of widely deployed platforms.
Insikt Group® reported 31 high-impact vulnerabilities under active exploitation in March, 29 of which carried a Very Critical Recorded Future Risk Score, signaling strong, real‑world attacker interest.
Nine of the 31 vulnerabilities enabled remote code execution (RCE), affecting Google, Langflow, Craft CMS, Laravel, Microsoft, n8n, SolarWinds, and Apple.
Insikt Group® also observed public proof‑of‑concept (PoC) exploits for 10 vulnerabilities, increasing the likelihood of rapid weaponization by additional threat actors and crimeware groups.
Nuclei templates were released for a path traversal bug in MindsDB (CVE-2026-27483), a critical missing authentication vulnerability in Nginx UI (CVE-2026-27944), and previously for n8n’s CVE-2025-68613, supporting faster detection and validation by defenders.
Interlock hits Cisco FMC zero‑day
The standout incident involved Interlock ransomware exploiting CVE-2026-20131, a critical deserialization vulnerability in Cisco Secure Firewall Management Center (FMC) and Cisco Security Cloud Control (SCC) firewall management.
The threat actors deploy a malicious ELF binary from a staging server at 37[.]27[.]244[.]222 (Intelligence Card) to support follow-on operations.

Cisco disclosed and patched the vulnerability on March 4, 2026, but Amazon’s threat intelligence revealed the group had been abusing it as a zero‑day since January 26, giving attackers more than a month’s lead time over defenders.
The bug stems from insecure deserialization of user‑supplied Java byte streams in FMC’s web interface, allowing unauthenticated remote attackers to submit crafted serialized objects and execute arbitrary Java code as root.
Interlock’s chain involves sending malicious HTTP requests to vulnerable FMC instances, then fetching an ELF payload from attacker infrastructure to establish persistence and support follow‑on operations.
Once inside, the group uses custom Java/JavaScript RATs, a memory‑resident web shell, and legitimate tools like ConnectWise ScreenConnect to move laterally, escalate privileges, and stage data for ransomware deployment.

Beyond Cisco, Recorded Future linked multiple exploitation chains to mobile and web ecosystems, with Apple and Google again in the crosshairs.
The DarkSword iOS full‑chain exploit enabled Safari‑based RCE, sandbox escape, and kernel‑level access, used to deploy GHOSTKNIFE, GHOSTSABER, and GHOSTBLADE payloads on compromised devices.
The Coruna exploit kit similarly targeted iOS, delivering the PlasmaLoader (PLASMAGRID) malware through browser‑driven exploit sequences.
Common weakness patterns this month included CWE‑502 (Deserialization of Untrusted Data) and CWE‑94 (Code Injection), reflecting attackers’ focus on input handling and complex serialization logic in modern platforms.
Two vulnerabilities and a 23‑exploit kit (12 mapped to specific CVEs) were directly tied to malware campaigns, emphasizing that exploitation is not theoretical but embedded in active attacker tooling.
Old CVEs, new compromises
Exploited vulnerabilities were recent: CVE-2017-7921, a Hikvision vulnerability from around nine years ago, remained under active abuse in March.
Its continued exploitation highlights how unpatched legacy systems provide reliable footholds even as new zero‑days grab headlines.
Insikt Group® stresses that defenders should not dismiss older CVEs, but instead prioritize based on observed exploitation, solid asset visibility, and compensating controls where patching is impossible.
For vulnerability management teams, March 2026 is a reminder that risk must be driven by threat intelligence, not just CVSS alone.
Organizations running Cisco FMC/SCC, Microsoft, Apple, and other heavily targeted products should urgently apply vendor patches, validate exposure against the 31 CVEs, and consider integrating Nuclei templates and Recorded Future risk scoring into their remediation workflows.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.





