Facebook Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Facebook products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
3
In CISA KEV
3
Beyond CISA KEV
0
Sensor Observed
0
Virtual Patch Available
0
Facebook KEVs Added by Year
3 Facebook KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-55177
Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78,... |
WhatsApp Desktop for Mac, WhatsApp Business for iOS, WhatsApp for iOS | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2019-3568
A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target... |
WhatsApp for Android, WhatsApp Business for Android, WhatsApp for iOS, WhatsApp Business for iOS, WhatsApp for Windows Phone, WhatsApp for Tizen | Confirmed | In CISA | 19 Apr 2022 |
|
CVE-2019-18426
A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site... |
WhatsApp Desktop | Confirmed | In CISA | 23 May 2022 |
Common Vulnerability Classes (CWE)
- CWE-122 — Heap-based Buffer Overflow 1
- CWE-79 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 1
- CWE-863 — Incorrect Authorization 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology