logo

Attackers hit React defect as researchers quibble over proof

ID: 51baa29f-26a6-5840-8ce9-a079c4a97038

STIX ID: report--51baa29f-26a6-5840-8ce9-a079c4a97038

Feed Name: CyberScoop

Threat Score
90/100

Date Published: 2025-12-05

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

A critical RCE deserialization flaw in React Server Components (React2Shell, CVE-2025-55182, CVSS 10) was patched publicly and quickly weaponized: multiple vendors and researchers report widespread scanning, active exploitation, and follow-on activity including credential theft, webshell deployment, cryptojacking, and downloader installations; evidence points to opportunistic criminal groups and state-linked actors (including UNC5174 and China-nexus groups), with CISA adding the CVE to its known exploited vulnerabilities catalog and dozens of organizations confirmed impacted.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.