logo

'Exploitation is imminent' as 39 percent of cloud environs have max-severity React hole

ID: 0d614d9d-db38-53bd-89f5-bdc4cbaa522f

STIX ID: report--0d614d9d-db38-53bd-89f5-bdc4cbaa522f

Feed Name: The Register (Security)

Threat Score
95/100

Date Published: 2025-12-03

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

**Executive Summary:** A critical unauthenticated remote code execution (RCE) vulnerability (CVE-2025-55182, CVSS 10.0) in React Server Components — impacting multiple React versions and default configurations of frameworks such as Next.js — allows attackers to send malicious HTTP requests to Server Function endpoints to achieve RCE; patches have been released (React 19.0.1, 19.1.2, 19.2.1 and Next.js updates) and immediate patching is strongly recommended due to widespread usage (estimated 39% of cloud environments) and the high likelihood of imminent mass exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.