2.15M Web Services Running Next.js Exposed Over Internet, Active Exploitation Underway – Patch Now
ID: 649cf3de-2f16-53d3-85d2-e6c25de2417b
STIX ID: report--649cf3de-2f16-53d3-85d2-e6c25de2417b
Feed Name: cybersecurityNews.com
A critical unauthenticated RCE in React Server Components (CVE-2025-55182, CVSS 10.0) is being actively exploited in the wild, with Amazon Web Services reporting China-nexus actors (Earth Lamia, Jackpot Panda) exploiting the flaw within 24 hours of disclosure; attackers are deploying web shells and backdoors against cloud-hosted applications. The vulnerability affects react-server-dom-* packages and dependent frameworks (Next.js, Waku, React Router, RedwoodSDK) across specified versions, CISA has listed it in its Known Exploited Vulnerabilities Catalog, and about 2.15 million internet-facing services may be exposed; immediate patching to fixed React/Next.js versions is recommended while WAF rules provide partial protection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
