logo

Microsoft Details Mitigations Against React2Shell RCE Vulnerability in React Server Components

ID: 7058ff36-a08a-5fd7-8073-ae70a87fdd9c

STIX ID: report--7058ff36-a08a-5fd7-8073-ae70a87fdd9c

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-12-16

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Microsoft reports React2Shell (CVE-2025-55182), a critical (CVSS 10.0) pre-auth RCE in React Server Components/Next.js that has been exploited in the wild; attackers use crafted POST requests to trigger prototype pollution and execute arbitrary Node.js code, then deploy backdoors (Cobalt Strike), various RATs and cryptominers, and steal cloud credentials to escalate and move laterally.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.