Exploitation timeline
Threadlinqs has recorded 5 Facebook CVEs published between and . The busiest month was 2025-12 (4 new CVEs). 2 of them (40%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 5 of 5 tracked Facebook CVEs.
- CVE-2025-55182critical 10KEVRansomwareEPSS 84.9%
- CVE-2019-3568critical 9.8KEVEPSS 39.2%
- CVE-2025-55184high 7.5EPSS 21.1%
- CVE-2025-55183medium 5.3EPSS 21%
- CVE-2025-67779high 7.5EPSS 0.2%
Products affected
Threadlinqs normalises CPE and CNA product records across all 5 CVEs; 7 distinct Facebook products are affected. The most frequently affected:
- React 4 CVEs
- WhatsApp Business for Android 1 CVE
- WhatsApp Business for iOS 1 CVE
- WhatsApp for Android 1 CVE
- WhatsApp for Tizen 1 CVE
- WhatsApp for Windows Phone 1 CVE
- WhatsApp for iOS 1 CVE
Threat activity
19 tracked threat campaigns reference Facebook products or exploit Facebook CVEs:
- The Gentlemen RaaS overtakes Qilin as #1 ransomware operation, wields GentleKiller EDR-killer framework (400+ processes, 8 BYOVD variants) and 90% affiliate payoutsHIGH
- FulcrumSec Double-Extortion Data Theft of Global Schools Foundation (GSF) EdTech Network via Unrotated 2022 MongoDB CredentialsHIGH
- The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS Affiliate ProgramCRITICAL
- Fake IT Support Calls on Microsoft Teams Push EtherRAT — Node.js RAT Using EtherHiding (Ethereum Smart Contract C2), Linked to React2Shell (CVE-2025-55182) Exploitation ChainHIGH
- SharkLoader Malware Campaign Uses Fake Cisco AnyConnect and Google Update Installers to Deploy Cobalt StrikeHIGH
- ChocoPoC RAT Campaign Uses Malicious PoC-Exploit Python Packages to Backdoor Security ResearchersHIGH
- ChocoPoC Campaign: Trojanised PoC Exploits and PyPI Packages Deliver Python RAT Using Mapbox Datasets API as Dead-Drop C2HIGH
- ChocoPoC: Python RAT Distributed via Trojanized PoC Exploits Targeting Security ResearchersHIGH
- SharkLoader Malware Deploys Cobalt Strike Beacon via DLL Side-Loading in StrikeShark CampaignHIGH
- NSO Group Pegasus Spyware — WhatsApp Spearphishing Campaign Alleged in Meta Contempt Complaint (June 2026)HIGH
- SHADOW-EARTH-053 — China-Aligned Cyberespionage Campaign Exploiting Microsoft Exchange (ProxyLogon CVE-2021-26855/26857/26858/27065) and IIS to Deploy GODZILLA Web Shells and ShadowPadHIGH
- PCPJack Worm — Cloud Credential Theft Framework Evicting TeamPCP Infections (CVE-2025-29927, CVE-2025-55182, CVE-2026-1357, CVE-2025-9501, CVE-2025-48703)CRITICAL
- Bissa Scanner — AI-Assisted Mass Exploitation of CVE-2025-55182 (React Server Components RCE) and CVE-2025-9501 (W3 Total Cache)CRITICAL
- Bissa Scanner — AI-Assisted Mass Exploitation and Credential Harvesting Campaign (@BonJoviGoesHard / Dr. Tube)HIGH
- Escalating Kubernetes Attacks: React2Shell (CVE-2025-55182), Slow Pisces, and Cloud-Native Threat ActorsCRITICAL
- TeamPCP LiteLLM Supply Chain Attack — Trojaned PyPI Packages (v1.82.7/1.82.8) with Multi-Stage C2 PayloadCRITICAL
- EtherRAT — Node.js Backdoor with Ethereum Blockchain C2 (EtherHiding) Linked to DPRK Contagious InterviewCRITICAL
- TeamPCP Partners With Vect Ransomware Group to Escalate Cross-Ecosystem Open Source Supply Chain AttacksCRITICAL
- React2Shell CVE-2025-55182 — Multiple Threat Actors Actively Exploiting React Server Components RCE (CVSS 10.0)CRITICAL
Threat actors targeting Facebook
Named threat actors attributed to campaigns that involve Facebook products or CVEs, with the number of linked campaigns:
How to prioritise Facebook patching
This order follows the data Threadlinqs holds for Facebook, not a generic severity checklist:
- 2 of 5 Facebook CVEs (40%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with CVE-2025-55182, CVE-2019-3568.
- 1 CVE is known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are CVE-2025-55184 (21.1%), CVE-2025-55183 (21%), CVE-2025-67779 (0.2%).
- 2 CVEs score Critical and 2 High on CVSS v3 (maximum 10, average 8); sequence these after KEV and high-EPSS items.
- 1 CVE has a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.