Federal agencies now only have one more day to patch React2Shell bug
ID: 090816de-b451-54f2-9b0d-385627f93780
STIX ID: report--090816de-b451-54f2-9b0d-385627f93780
Feed Name: The Record from Recorded Future News
CVE-2025-55182 (React2Shell), a vulnerability in React Server Components embedded in millions of sites and products, is being actively exploited by state-linked actors (China, North Korea) and numerous cybercriminal groups to deliver cryptominers, botnets, backdoors and other malware. CISA added the CVE to its Known Exploited Vulnerabilities catalog with an accelerated patch deadline, and multiple security firms (Unit 42, Rapid7, CyCognito) report global compromises across government, finance, media, education and other sectors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
