# Facebook vulnerabilities & exploitation

**CISA KEV** · **Ransomware**

> As of 2026-10-05, Threadlinqs tracks 5 Facebook CVEs, 2 in the CISA Known Exploited Vulnerabilities catalog, 1 used in ransomware campaigns, linked to 19 tracked threat campaigns and 12 named threat actors.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 5 Facebook CVEs published between 2019-05-15 and 2025-12-15. The busiest month was 2025-12 (4 new CVEs). 2 of them (40%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 5 of 5 tracked Facebook CVEs.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182) — CRITICAL 10 · KEV · Ransomware · EPSS 84.9% · 2025-12-03
- [CVE-2019-3568](https://intel.threadlinqs.com/cve/CVE-2019-3568) — CRITICAL 9.8 · KEV · EPSS 39.2% · 2019-05-14
- [CVE-2025-55184](https://intel.threadlinqs.com/cve/CVE-2025-55184) — HIGH 7.5 · EPSS 21.1% · 2025-12-11
- [CVE-2025-55183](https://intel.threadlinqs.com/cve/CVE-2025-55183) — MEDIUM 5.3 · EPSS 21% · 2025-12-11
- [CVE-2025-67779](https://intel.threadlinqs.com/cve/CVE-2025-67779) — HIGH 7.5 · EPSS 0.2% · 2025-12-12

## Products affected

Threadlinqs normalises CPE and CNA product records across all 5 CVEs; 7 distinct Facebook products are affected. The most frequently affected:

- React — 4 CVEs
- WhatsApp Business for Android — 1 CVE
- WhatsApp Business for iOS — 1 CVE
- WhatsApp for Android — 1 CVE
- WhatsApp for Tizen — 1 CVE
- WhatsApp for Windows Phone — 1 CVE
- WhatsApp for iOS — 1 CVE

## Threat activity

19 tracked threat campaigns reference Facebook products or exploit Facebook CVEs:

- [The Gentlemen RaaS overtakes Qilin as #1 ransomware operation, wields GentleKiller EDR-killer framework (400+ processes, 8 BYOVD variants) and 90% affiliate payouts](https://intel.threadlinqs.com/threat/TL-2026-1332) — HIGH — 2026-07-14
- [FulcrumSec Double-Extortion Data Theft of Global Schools Foundation (GSF) EdTech Network via Unrotated 2022 MongoDB Credentials](https://intel.threadlinqs.com/threat/TL-2026-1209) — HIGH — 2026-07-11
- [The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS Affiliate Program](https://intel.threadlinqs.com/threat/TL-2026-1138) — CRITICAL — 2026-07-06
- [Fake IT Support Calls on Microsoft Teams Push EtherRAT — Node.js RAT Using EtherHiding (Ethereum Smart Contract C2), Linked to React2Shell (CVE-2025-55182) Exploitation Chain](https://intel.threadlinqs.com/threat/TL-2026-1141) — HIGH — 2026-07-06
- [SharkLoader Malware Campaign Uses Fake Cisco AnyConnect and Google Update Installers to Deploy Cobalt Strike](https://intel.threadlinqs.com/threat/TL-2026-1101) — HIGH — 2026-07-03
- [ChocoPoC RAT Campaign Uses Malicious PoC-Exploit Python Packages to Backdoor Security Researchers](https://intel.threadlinqs.com/threat/TL-2026-1062) — HIGH — 2026-07-02
- [ChocoPoC Campaign: Trojanised PoC Exploits and PyPI Packages Deliver Python RAT Using Mapbox Datasets API as Dead-Drop C2](https://intel.threadlinqs.com/threat/TL-2026-1088) — HIGH — 2026-07-02
- [ChocoPoC: Python RAT Distributed via Trojanized PoC Exploits Targeting Security Researchers](https://intel.threadlinqs.com/threat/TL-2026-1125) — HIGH — 2026-07-01
- [SharkLoader Malware Deploys Cobalt Strike Beacon via DLL Side-Loading in StrikeShark Campaign](https://intel.threadlinqs.com/threat/TL-2026-0961) — HIGH — 2026-06-27
- [NSO Group Pegasus Spyware — WhatsApp Spearphishing Campaign Alleged in Meta Contempt Complaint (June 2026)](https://intel.threadlinqs.com/threat/TL-2026-0728) — HIGH — 2026-06-09
- [SHADOW-EARTH-053 — China-Aligned Cyberespionage Campaign Exploiting Microsoft Exchange (ProxyLogon CVE-2021-26855/26857/26858/27065) and IIS to Deploy GODZILLA Web Shells and ShadowPad](https://intel.threadlinqs.com/threat/TL-2026-0493) — HIGH — 2026-05-11
- [PCPJack Worm — Cloud Credential Theft Framework Evicting TeamPCP Infections (CVE-2025-29927, CVE-2025-55182, CVE-2026-1357, CVE-2025-9501, CVE-2025-48703)](https://intel.threadlinqs.com/threat/TL-2026-0478) — CRITICAL — 2026-05-07
- [Bissa Scanner — AI-Assisted Mass Exploitation of CVE-2025-55182 (React Server Components RCE) and CVE-2025-9501 (W3 Total Cache)](https://intel.threadlinqs.com/threat/TL-2026-0428) — CRITICAL — 2026-04-27
- [Bissa Scanner — AI-Assisted Mass Exploitation and Credential Harvesting Campaign (@BonJoviGoesHard / Dr. Tube)](https://intel.threadlinqs.com/threat/TL-2026-0411) — HIGH — 2026-04-22
- [Escalating Kubernetes Attacks: React2Shell (CVE-2025-55182), Slow Pisces, and Cloud-Native Threat Actors](https://intel.threadlinqs.com/threat/TL-2026-0327) — CRITICAL — 2026-04-06
- [TeamPCP LiteLLM Supply Chain Attack — Trojaned PyPI Packages (v1.82.7/1.82.8) with Multi-Stage C2 Payload](https://intel.threadlinqs.com/threat/TL-2026-0304) — CRITICAL — 2026-03-31
- [EtherRAT — Node.js Backdoor with Ethereum Blockchain C2 (EtherHiding) Linked to DPRK Contagious Interview](https://intel.threadlinqs.com/threat/TL-2026-0293) — CRITICAL — 2026-03-27
- [TeamPCP Partners With Vect Ransomware Group to Escalate Cross-Ecosystem Open Source Supply Chain Attacks](https://intel.threadlinqs.com/threat/TL-2026-0288) — CRITICAL — 2026-03-26
- [React2Shell CVE-2025-55182 — Multiple Threat Actors Actively Exploiting React Server Components RCE (CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-0080) — CRITICAL — 2026-02-13

## Threat actors targeting Facebook

Named threat actors attributed to campaigns that involve Facebook products or CVEs, with the number of linked campaigns:

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 3 campaigns
- [BonJoviGoesHard](https://intel.threadlinqs.com/actor/BonJoviGoesHard) — 2 campaigns
- [Earth Lamia](https://intel.threadlinqs.com/actor/Earth%20Lamia) — 1 campaign
- [Jade Sleet](https://intel.threadlinqs.com/actor/Jade%20Sleet) — 1 campaign
- [NSO Group](https://intel.threadlinqs.com/actor/NSO%20Group) — 1 campaign
- [PCPJack](https://intel.threadlinqs.com/actor/PCPJack) — 1 campaign
- [SHADOW-EARTH-053](https://intel.threadlinqs.com/actor/SHADOW-EARTH-053) — 1 campaign
- [Slow Pisces](https://intel.threadlinqs.com/actor/Slow%20Pisces) — 1 campaign
- [StrikeShark](https://intel.threadlinqs.com/actor/StrikeShark) — 1 campaign
- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 1 campaign
- [TraderTraitor](https://intel.threadlinqs.com/actor/TraderTraitor) — 1 campaign
- [Vect Ransomware](https://intel.threadlinqs.com/actor/Vect%20Ransomware) — 1 campaign

## How to prioritise Facebook patching

This order follows the data Threadlinqs holds for Facebook, not a generic severity checklist:

- 2 of 5 Facebook CVEs (40%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182), [CVE-2019-3568](https://intel.threadlinqs.com/cve/CVE-2019-3568).
- 1 CVE is known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are [CVE-2025-55184](https://intel.threadlinqs.com/cve/CVE-2025-55184) (21.1%), [CVE-2025-55183](https://intel.threadlinqs.com/cve/CVE-2025-55183) (21%), [CVE-2025-67779](https://intel.threadlinqs.com/cve/CVE-2025-67779) (0.2%).
- 2 CVEs score Critical and 2 High on CVSS v3 (maximum 10, average 8); sequence these after KEV and high-EPSS items.
- 1 CVE has a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/facebook
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
