PULSE NAME
March 2026 CVE Landscape: 31 High-Impact Vulnerabilities Identified, Interlock Ransomware Group Exploits Cisco FMC Zero-Day
WHITE Interlock Ransomware Group AlienVault 2026-04-14 Modified: 2026-04-14
27
IOCs
MEDIUM VOLUME
In March 2026, 31 high-impact vulnerabilities were identified requiring prioritization for remediation, with 29 receiving Very Critical Risk Scores. Affected vendors included Cisco, Microsoft, Google, ConnectWise, and others, with Microsoft and Apple accounting for approximately 32% of vulnerabilities. Notably, the Interlock Ransomware Group exploited CVE-2026-20131, a zero-day deserialization vulnerability in Cisco Secure Firewall Management Center, as early as January 2026 to compromise enterprise networks. The group deployed custom remote access trojans and facilitated ransomware operations through crafted HTTP requests executing arbitrary Java code as root. Additional campaigns involved the DarkSword iOS exploit kit delivering GHOSTKNIFE, GHOSTSABER, and GHOSTBLADE payloads, and the Coruna exploit kit deploying PlasmaLoader malware. Nine vulnerabilities enabled remote code execution across multiple platforms. One vulnerability dated back nine years, emphasizing continued exploitation of legacy unpatched
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
GHOSTKNIFE GHOSTSABER GHOSTBLADE PlasmaLoader PLASMAGRID
Indicators of Compromise (27)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2017-7921 2026-04-14
CVE CVE-2021-30952 2026-04-14
CVE CVE-2023-41974 2026-04-14
CVE CVE-2025-26399 2026-04-14
CVE CVE-2025-32432 2026-04-14
CVE CVE-2025-53521 2026-04-14
CVE CVE-2025-54068 2026-04-14
CVE CVE-2025-68613 2026-04-14
CVE CVE-2026-20131 2026-04-14
CVE CVE-2026-20963 2026-04-14
CVE CVE-2026-21262 2026-04-14
CVE CVE-2026-21385 2026-04-14
CVE CVE-2026-25187 2026-04-14
CVE CVE-2026-26127 2026-04-14
CVE CVE-2026-27483 2026-04-14
CVE CVE-2026-27944 2026-04-14
CVE CVE-2026-3055 2026-04-14
CVE CVE-2026-33017 2026-04-14
CVE CVE-2026-33032 2026-04-14
CVE CVE-2026-33634 2026-04-14
CVE CVE-2026-3564 2026-04-14
CVE CVE-2026-3909 2026-04-14
CVE CVE-2026-3910 2026-04-14
FileHash-MD5 12d399e6966db58f6d189d606ac34cc8 2026-04-14
FileHash-SHA1 17986b6595fe960fe8e9757d3069d5daabd628ef 2026-04-14
FileHash-SHA256 6c8efbcef3af80a574cb2aa2224c145bb2e37c2f3d3f091571708288ceb22d5f 2026-04-14
IPv4 37.27.244.222 2026-04-14