Critical React2Shell RCE Vulnerability Exploited in the Wild to Execute Malicious Code
ID: fd71ec1e-460d-5e56-a741-179d840e559e
STIX ID: report--fd71ec1e-460d-5e56-a741-179d840e559e
Feed Name: cybersecurityNews.com
A critical unauthenticated RCE in React Server Components (CVE-2025-55182, "React2Shell") is being actively exploited in the wild. GreyNoise observed automated scanning and exploitation leveraging public PoC code, PowerShell arithmetic probes to validate execution, encoded PowerShell stagers with AMSI bypass, and integration into Mirai and other botnet exploitation kits; defenders are advised to urgently patch affected React/Next.js deployments, monitor for characteristic PowerShell activity, and block malicious IPs/JA4/ASN indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
