Facebook vendor intelligence
Facebook Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Facebook products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 3
- Known exploited vulnerabilities affecting Facebook products
- In CISA KEV
- 3
- Records also listed in the official catalog
- Beyond CISA KEV
- 0
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 0
- Facebook KEVs with sensor-observed exploitation activity
The catalog gap matters for Facebook exposure
All three exploited Facebook CVEs tracked here are also listed in CISA KEV. Use product ownership and sensor evidence to prioritize within this portfolio.
- 100%
- Covered by CISA
- 0%
- Beyond CISA
- 3
- Product families
Attested Facebook CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-55177
Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78,... |
WhatsApp Desktop for Mac, WhatsApp Business for iOS, WhatsApp for iOS | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2019-3568
A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target... |
WhatsApp for Android, WhatsApp Business for Android, WhatsApp for iOS, WhatsApp Business for iOS, WhatsApp for Windows Phone, WhatsApp for Tizen | Confirmed | In CISA | 19 Apr 2022 |
|
CVE-2019-18426
A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site... |
WhatsApp Desktop | Confirmed | In CISA | 23 May 2022 |
No Facebook CVEs match this search or filter.
Showing 3 of 3 Facebook known exploited vulnerabilities.
Recurring weakness patterns
Heap-based buffer overflow, neutralization, and incorrect authorization account for three mapped occurrences across this Facebook KEV portfolio.
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.