React Under Siege: Two IPs Drive 56% of Critical CVE-2025-55182 Attacks
ID: 9d81dfda-fe2c-546a-858a-37fd882fdf19
STIX ID: report--9d81dfda-fe2c-546a-858a-37fd882fdf19
Feed Name: securityonline.info
Threat Score
GreyNoise reports that CVE-2025-55182 (a CVSS 10.0 RCE in React Server Components) is being actively and widely exploited: two IPs account for 56% of observed attempts, attackers are deploying cryptominers and reverse shells, and default React dev ports (3000–3002) and internet-facing development servers are heavily targeted—organizations should assume they may have been targeted and upgrade to patched React versions immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
