logo

React2Shell Vulnerability Hit by 8.1 Million Attack Attempts

ID: e1cb0d39-0d98-5bce-a692-b59de0ca974b

STIX ID: report--e1cb0d39-0d98-5bce-a692-b59de0ca974b

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-01-08

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A critical RCE vulnerability in the React Server Components Flight protocol (CVE-2025-55182, “React2Shell”) is being widely exploited in a massive campaign: GreyNoise observed over 8.1 million attack sessions with daily volumes of 300k–400k, originating from 8,163 unique IPs across 1,071 ASNs in 101 countries. Attackers deploy thousands of unique payloads and use encoded PowerShell stagers with AMSI bypass techniques; the report urges immediate patching, dynamic cloud-focused blocking, and endpoint detections for PowerShell/AMSI reflection patterns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.