logo

Hackers Exploiting React Server Components Vulnerability in the Wild to Deploy Malicious Payloads

ID: f09d0e88-2163-5a35-92e0-29e9a4523995

STIX ID: report--f09d0e88-2163-5a35-92e0-29e9a4523995

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-02-04

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Active exploitation of CVE-2025-55182 (critical deserialization RCE in React Server Components, CVSS 10.0) has progressed from broad scanning to concentrated, high-volume campaigns using a public Metasploit module. GreyNoise telemetry (Jan 26–Feb 2, 2026) shows two dominant actors: one dropping XMRig cryptominers from staging servers and another opening reverse shells back to scanner IPs for interactive access; notable infrastructure includes attacker IPs 87.121.84.24 and 193.142.147.209 and staging host 205.185.127.97. Organizations are urged to patch to patched React versions or restrict access to development ports (e.g., 3000–3002) and block listed IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.