CVE detail
CVE-2026-23863
An attachment spoofing issue in WhatsApp for Windows prior to v2.3000.1032164386.258709 could have allowed maliciously formatted documents with embedded NUL bytes in the filename to be shown in the application as one type of file but run as an executable when opened. We have not seen evidence of exploitation in the wild.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 13.9 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
3 source links · newest first
The vulnerabilities were reported to Meta through its bug bounty program and were patched with updates released earlier this year.
newswww.securityweek.comMay 5, 2026, 9:01 AM- https://www.whatsapp.com/security/advisories/2026www.whatsapp.com
No excerpt available.
Vendor Advisorywww.whatsapp.comMay 1, 2026, 4:16 PM - https://www.facebook.com/security/advisories/cve-2026-23863www.facebook.com
No excerpt available.
Vendor Advisorywww.facebook.comMay 1, 2026, 4:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-47778CVSS 4.4 · Medium
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a structural flaw was identified in DefaultCer…
- CVE-2026-43895CVSS 4.4 · Medium
jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string…
- CVE-2026-41256CVSS 5.5 · Medium
jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD.…
- CVE-2026-43861CVSS 3.7 · Low
mutt before 2.3.2 does not check for '\0' in url_pct_decode.
- CVE-2026-43859CVSS 3.7 · Low
mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.
- CVE-2026-33191CVSS 8.7 · High
Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions prior to 1.4.2 are vulnerable to null byte injection in URL path paramete…