Exploitation Activity Ramps Up Against React2Shell
ID: a859439d-721c-50fc-89af-4a8b2ed73724
STIX ID: report--a859439d-721c-50fc-89af-4a8b2ed73724
Feed Name: Dark Reading
Threat Score
React2Shell (CVE-2025-55182) is a critical RCE deserialization flaw in React Server Components that received a CVSS of 10 and has been exploited in the wild within hours of disclosure; attackers are rapidly targeting internet-facing Next.js and other RSC-based deployments for cryptomining, credential theft, and backdoor campaigns, with researchers and scanners reporting widespread exploitation attempts, millions of exposed services, and some WAF-bypass techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
