logo

React2Shell fallout spreads to sensitive targets as public exploits hit all-time high

ID: d24a4ea6-a852-50d8-b682-e0bcc6762763

STIX ID: report--d24a4ea6-a852-50d8-b682-e0bcc6762763

Feed Name: CyberScoop

Threat Score
92/100

Date Published: 2025-12-17

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

React2Shell (CVE-2025-55182) is a critical remote-code-execution vulnerability in React Server Components that has seen rapid, widespread exploitation since disclosure: hundreds of public exploits exist, multiple nation-state groups and criminal gangs are leveraging it, and incidents include reverse shells, lateral movement, data theft and rapid ransomware deployment (e.g., Weaxor). Researchers and vendors report dozens to hundreds of compromised machines and urge urgent patching and remediation as active exploitation continues to escalate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.