CISA Adds Critical React2Shell Vulnerability to KEV Catalog Following Active Exploitation
ID: e36ac20d-625d-5a60-8410-7685f530c747
STIX ID: report--e36ac20d-625d-5a60-8410-7685f530c747
Feed Name: cybersecurityNews.com
A critical unauthenticated remote code execution vulnerability in Meta React Server Components (CVE-2025-55182) has been added to CISA’s Known Exploited Vulnerabilities catalog due to active exploitation. CISA assigned a critical severity and set a 21-day remediation deadline for federal agencies (added Dec 5, 2025; remediation by Dec 26, 2025). Organizations are advised to apply vendor mitigations, follow guidance for cloud services, or discontinue affected deployments if patches cannot be implemented, and to monitor threat intelligence for developments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
