PULSE NAME
March 2026 CVE Landscape: 31 High-Impact Vulnerabilities Identified, Interlock Ransomware Group Exploits Cisco FMC Zero-Day
WHITE Interlock Ransomware Group AlienVault 2026-04-14 Modified: 2026-04-14
27
IOCs
MEDIUM VOLUME
In March 2026, 31 high-impact vulnerabilities were identified requiring prioritization for remediation, with 29 receiving Very Critical Risk Scores. Affected vendors included Cisco, Microsoft, Google, ConnectWise, and others, with Microsoft and Apple accounting for approximately 32% of vulnerabilities. Notably, the Interlock Ransomware Group exploited CVE-2026-20131, a zero-day deserialization vulnerability in Cisco Secure Firewall Management Center, as early as January 2026 to compromise enterprise networks. The group deployed custom remote access trojans and facilitated ransomware operations through crafted HTTP requests executing arbitrary Java code as root. Additional campaigns involved the DarkSword iOS exploit kit delivering GHOSTKNIFE, GHOSTSABER, and GHOSTBLADE payloads, and the Coruna exploit kit deploying PlasmaLoader malware. Nine vulnerabilities enabled remote code execution across multiple platforms. One vulnerability dated back nine years, emphasizing continued exploitation of legacy unpatched
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
GHOSTKNIFE GHOSTSABER GHOSTBLADE PlasmaLoader PLASMAGRID
Indicators of Compromise (23 / 27 total)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2017-7921 2026-04-14
CVE CVE-2021-30952 2026-04-14
CVE CVE-2023-41974 2026-04-14
CVE CVE-2025-26399 2026-04-14
CVE CVE-2025-32432 2026-04-14
CVE CVE-2025-53521 2026-04-14
CVE CVE-2025-54068 2026-04-14
CVE CVE-2025-68613 2026-04-14
CVE CVE-2026-20131 2026-04-14
CVE CVE-2026-20963 2026-04-14
CVE CVE-2026-21262 2026-04-14
CVE CVE-2026-21385 2026-04-14
CVE CVE-2026-25187 2026-04-14
CVE CVE-2026-26127 2026-04-14
CVE CVE-2026-27483 2026-04-14
CVE CVE-2026-27944 2026-04-14
CVE CVE-2026-3055 2026-04-14
CVE CVE-2026-33017 2026-04-14
CVE CVE-2026-33032 2026-04-14
CVE CVE-2026-33634 2026-04-14
CVE CVE-2026-3564 2026-04-14
CVE CVE-2026-3909 2026-04-14
CVE CVE-2026-3910 2026-04-14