logo

Hackers Exploit Next.js React2Shell Vulnerability, Breach 766 Hosts in 24 Hours

ID: 4293b3da-2b15-5759-a288-a384299e57fd

STIX ID: report--4293b3da-2b15-5759-a288-a384299e57fd

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-04-07

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Cisco Talos details an active mass-exploitation campaign (UAT-10608) abusing CVE-2025-55182 (React2Shell) in Next.js to achieve pre-auth RCE and deploy automated harvesting scripts that exfiltrate environment variables, SSH keys, cloud credentials, API keys and other secrets to a NEXUS Listener C2; telemetry shows at least 766 compromised hosts and 10,120 files exfiltrated, and defenders are urged to patch, rotate secrets, and harden server-side configurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.