logo

Hackers Launched 8.1 Million Attack Sessions to React2Shell Vulnerability

ID: 6c215a07-1c4c-5479-a571-b1c33a6c705c

STIX ID: report--6c215a07-1c4c-5479-a571-b1c33a6c705c

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-01-08

Date Updated: 2026-04-21

Author: Abinaya

...
...

**React2Shell (CVE-2025-55182) is being actively and widely exploited** — the campaign has generated over 8.1 million attack sessions with daily volumes of 300k–400k, leveraging a distributed, cloud-heavy infrastructure (8,163 source IPs across 1,071 ASNs in 101 countries), over 70,000 unique payloads, numerous HTTP/TCP fingerprints, and a two-stage PowerShell exploitation flow employing AMSI bypass; organizations should urgently patch exposed React Server Components, implement dynamic blocking and endpoint monitoring for encoded PowerShell and AMSI tampering.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.