logo

Critical React2Shell RCE Vulnerability Exploited in the Wild to Execute Malicious Code

ID: fd71ec1e-460d-5e56-a741-179d840e559e

STIX ID: report--fd71ec1e-460d-5e56-a741-179d840e559e

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2025-12-08

Date Updated: 2026-04-21

Author: Abinaya

...
...

A critical unauthenticated RCE in React Server Components (CVE-2025-55182, "React2Shell") is being actively exploited in the wild. GreyNoise observed automated scanning and exploitation leveraging public PoC code, PowerShell arithmetic probes to validate execution, encoded PowerShell stagers with AMSI bypass, and integration into Mirai and other botnet exploitation kits; defenders are advised to urgently patch affected React/Next.js deployments, monitor for characteristic PowerShell activity, and block malicious IPs/JA4/ASN indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.