logo

Half of exposed React servers remain unpatched amid active exploitation

ID: 25791a14-6d49-5422-bf82-cf9b1e1ab682

STIX ID: report--25791a14-6d49-5422-bf82-cf9b1e1ab682

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2025-12-12

Date Updated: 2026-04-26

Author: Carly Page

...
...

The report details widespread, active exploitation of CVE-2025-55182 (“React2Shell”), a critical RCE in React Server Components and dependent frameworks (e.g., Next.js). Telemetry indicates roughly 50% of internet-facing vulnerable instances remain unpatched, and at least 15 distinct intrusion clusters are observed — ranging from commodity cryptomining operations (Kinsing, C3Pool) to suspected nation-state-linked actors using hands-on-keyboard tooling (Sliver), backdoors (EtherRat, BPFDoor), bespoke injectors, and anti-forensics — enabling rapid, industrialized compromise at scale.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.