logo

React Under Siege: Two IPs Drive 56% of Critical CVE-2025-55182 Attacks

ID: 9d81dfda-fe2c-546a-858a-37fd882fdf19

STIX ID: report--9d81dfda-fe2c-546a-858a-37fd882fdf19

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-02-04

Date Updated: 2026-04-23

Author: Ddos

...
...

GreyNoise reports that CVE-2025-55182 (a CVSS 10.0 RCE in React Server Components) is being actively and widely exploited: two IPs account for 56% of observed attempts, attackers are deploying cryptominers and reverse shells, and default React dev ports (3000–3002) and internet-facing development servers are heavily targeted—organizations should assume they may have been targeted and upgrade to patched React versions immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.