Interlock Ransomware CVE-2026-20131 Cisco FMC Java RCE Payload

This rule detects HTTP POST requests targeting Cisco Firepower Management Center (FMC) that contain Java exploitation patterns (Runtime.getRuntime or ProcessBuilder) associated with the exploitation of CVE-2026-20131. This activity is indicative of an attempt to achieve Remote Code Execution (RCE) on the FMC appliance, likely by an actor utilizing the Interlock Ransomware threat.