Cyberkendra WhatsApp Addresses Instagram Reels URL Vulnerability, CVE-2026-23866
Article Content
- •CVE-2026-23866 allows URL redirection leading to IP address leakage.
- •The vulnerability affects specific WhatsApp versions on iOS and Android.
- •A researcher confirmed a one-click exploit but not the zero-click variant.
On October 6, 2026, Cyberkendra reported that WhatsApp patched CVE-2026-23866, a vulnerability allowing attackers to exploit Instagram Reels URLs to leak sensitive information like IP addresses and headers. The flaw, disclosed by Meta on May 1, 2026, affects WhatsApp versions 2.25.8.0 to 2.26.15.72 on iOS and 2.25.8.0 to 2.26.7.10 on Android. The vulnerability arises from incomplete validation of AI-rich response messages, which could let a crafted message redirect users to malicious URLs. A researcher, known as Numb3rs, confirmed a one-click attack vector but could not reproduce the more severe zero-click exploit. Meta has stated there is no evidence of exploitation in the wild. Users are advised to update to the latest WhatsApp versions to mitigate this risk.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Meta and CVE-2026-23863 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which WhatsApp versions are affected?
Is there evidence of exploitation?
What should users do?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…