Attackers hit React defect as researchers quibble over proof
ID: 51baa29f-26a6-5840-8ce9-a079c4a97038
STIX ID: report--51baa29f-26a6-5840-8ce9-a079c4a97038
Feed Name: CyberScoop
A critical RCE deserialization flaw in React Server Components (React2Shell, CVE-2025-55182, CVSS 10) was patched publicly and quickly weaponized: multiple vendors and researchers report widespread scanning, active exploitation, and follow-on activity including credential theft, webshell deployment, cryptojacking, and downloader installations; evidence points to opportunistic criminal groups and state-linked actors (including UNC5174 and China-nexus groups), with CISA adding the CVE to its known exploited vulnerabilities catalog and dozens of organizations confirmed impacted.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
