logo

React2Shell Remote Code Execution

ID: 1fed4944-614b-5941-82ad-86a236bbc368

STIX ID: report--1fed4944-614b-5941-82ad-86a236bbc368

Feed Name: FortiGuard Labs | FortiGuard Center - Outbreak Alerts

Threat Score
92/100

Date Published: 2026-04-02

Date Updated: 2026-07-28

...
...

**Executive Summary:** React2Shell is a critical unauthenticated remote code execution (RCE) vulnerability in React Server Components and Flight-implementing frameworks (including Next.js) tracked as CVE-2025-55182/CVE-2025-66478; it is being actively exploited in the wild, has been added to CISA's KEV catalog, and has been observed leveraging infrastructure tied to China-nexus actors—organizations should urgently apply vendor patches, enforce WAF protections on RSC/Flight endpoints, and perform proactive threat hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.