logo

2.15M Web Services Running Next.js Exposed Over Internet, Active Exploitation Underway – Patch Now

ID: 649cf3de-2f16-53d3-85d2-e6c25de2417b

STIX ID: report--649cf3de-2f16-53d3-85d2-e6c25de2417b

Feed Name: cybersecurityNews.com

Threat Score
95/100

Date Published: 2025-12-06

Date Updated: 2026-04-21

Author: Abinaya

...
...

A critical unauthenticated RCE in React Server Components (CVE-2025-55182, CVSS 10.0) is being actively exploited in the wild, with Amazon Web Services reporting China-nexus actors (Earth Lamia, Jackpot Panda) exploiting the flaw within 24 hours of disclosure; attackers are deploying web shells and backdoors against cloud-hosted applications. The vulnerability affects react-server-dom-* packages and dependent frameworks (Next.js, Waku, React Router, RedwoodSDK) across specified versions, CISA has listed it in its Known Exploited Vulnerabilities Catalog, and about 2.15 million internet-facing services may be exposed; immediate patching to fixed React/Next.js versions is recommended while WAF rules provide partial protection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.