Skip to content

CVE-2026-23866

CVE

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
May 2, 2026
Last Seen
June 6, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

Meta has disclosed and patched two medium severity security flaws in WhatsApp, affecting users on Windows, iPhone, and Android. The more critical vulnerability, CVE-2026-23863, allows malicious documents to appear harmless due to an attachment spoofing issue. This flaw affects WhatsApp for Windows v...

Meta has disclosed a medium-severity vulnerability in WhatsApp, tracked as CVE-2026-23866, which allows attackers to exploit the integration with Instagram Reels. This flaw enables remote threat actors to trigger arbitrary URL processing on victim devices without user consent by leveraging unvalidat...

Meta has disclosed two vulnerabilities in WhatsApp, CVE-2026-23863 and CVE-2026-23866, in a security advisory published on May 1, 2026. Both vulnerabilities were discovered through Meta's bug bounty program and are rated as medium severity. CVE-2026-23863 affects WhatsApp for Windows and involves an...

Public Exploits

Checking GitHub for proof-of-concept code…