CISA’s KEV listing changes the N-central posture from suspected activity to known exploitation of CVE-2026-86218 somewhere in the wild. N-able confirms critical pre-authentication RCE before 2026.3 HF4, build 2026.3.1.14, but neither source establishes exploit mechanics, affected victims, scale, or attribution. The reported CVE-2026-86206/86207 administrator-account chain remains only moderately supported without primary analysis or independent reproduction. Internet-reachable affected servers should therefore be treated as potentially compromised—not declared breached—while teams preserve snapshots and logs, isolate management exposure, patch, and audit privileged accounts, tokens, credentials, and role changes.
On Windows, the patch-count discrepancy—964, 973, or 974—does not alter the operational priority. CVE-2026-81963 and CVE-2026-85880 are actively exploited paths from an existing authenticated foothold or local execution to SYSTEM, not remote entry points. Same-day deployment should begin with validated canaries, then move through privileged workstations, jump hosts, shared systems and incident-response endpoints, followed by management, identity and exposed servers under controlled rollout gates, and finally the broader fleet.
WeWorm presents a demonstrated zero-click, cross-platform propagation capability in WeChat’s VoIP stack, but not evidence of in-the-wild exploitation or whole-device compromise. Tencent’s server-side mitigation materially reduces immediate exposure, although its independent validation and coverage of unofficial builds are unclear. Enterprises should still enforce WeChat 8.0.76 or later on iOS and 8.0.77 or later on Android; an old client or missed call alone does not justify emergency isolation.
The next set of checks applies the same evidentiary discipline to access infrastructure, development trust, identity theft, and crypto exploitation: F5 BIG-IP APM, UNC6780/DUSTMAKER, BigBear 2.0, and the Hemi Genesis Drop claims.