The Cisco picture is now much sharper: an internet-reachable, unpatched FMC is exposed, but that alone does not prove compromise. The strongest execution evidence is /var/log/messages showing package_info.pl /var/tmp/license.tmp running as root. Talos also observed home.jsp, cmd.jar, credential theft, Netcat reverse shells, proxy tooling, and a Cyclops Blink variant. CVE-2026-20079 can provide unauthenticated root execution by itself; CVE-2026-20316 was used alongside it in one cluster, so we should not present the pair as a mandatory chain in every intrusion.
For the next 30 minutes, the defensible sequence is to remove FMC management from internet reach, preserve logs and appliance state, run Cisco’s published log check, and isolate systems showing the license-file execution pattern, known payloads, or associated network indicators. Patching blocks future exploitation but cannot be assumed to remove web shells, command tooling, or stolen credentials. Root access also puts FMC’s management identity at risk—including administrator sessions, API and service credentials, authentication configuration, backups, and certificate material used to manage firewalls. That does not automatically make every managed firewall compromised, but it does justify treating the fleet as at risk while hunting for unauthorized deployments, configuration changes, certificate replacement, or local execution. Confirmed payload or C2 evidence should push recovery toward Cisco-assisted rebuilding from known-good media and broad credential and trust revocation, not patch-only closure.
The N-central version conflict is also resolved: Hotfix 4, build 2026.3.1.14, supersedes Hotfix 3, and on-premises systems below .14 should be upgraded; hosted customers do not patch the service themselves. Active exploitation of CVE-2026-86218 is confirmed, while victim scope, mechanics, attribution, and the proposed rogue-admin chain remain unverified. We now turn from appliance compromise to tonight’s broader response queue: client-side Chrome and Windows exposure, whether the WeChat zero-click story has materially changed, the evidentiary limits around the FamousSparrow Exchange report, and the operational business impact for MSPs running N-central.