logo

Active exploitation notice: React2Shell critical vulnerability (CVE-2025-55182)

ID: 6029dfb8-0e91-5e73-b180-8af61031fcf3

STIX ID: report--6029dfb8-0e91-5e73-b180-8af61031fcf3

Feed Name: Expel Blog

Threat Score
90/100

Date Published: 2025-12-09

Date Updated: 2026-04-27

Author: Aaron Walton; Matt Jastram

...
...

Expel Intel warns of a critical, actively exploited vulnerability (CVE-2025-55182) impacting React Server and Next.js that enables remote code execution; proof-of-concepts were publicly used within days of disclosure and an estimated 60,000 servers were exposed. The report urges immediate patching, scanning for vulnerable apps (on-prem and cloud), and hunting ingress logs for specific request headers and serialized payload patterns (e.g., next-action, Rsc-action-id, "$@", "status":"resolved_model", and function constructors) to detect exploitation attempts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.