React2Shell and related RSC vulnerabilities threat brief: early exploitation activity and threat actor techniques
ID: 4cfe7d8c-19a5-5581-8414-137eb383a9b6
STIX ID: report--4cfe7d8c-19a5-5581-8414-137eb383a9b6
Feed Name: Cloudflare Blog
On December 3, 2025 Cloudflare observed immediate, large-scale scanning and active exploitation attempts targeting a critical React Server Components RCE (CVE-2025-55182, "React2Shell") and two related RSC vulnerabilities (CVE-2025-55183, CVE-2025-55184); activity included use of Nuclei, custom React2Shell scanners, Burp Suite, and Internet-scale asset discovery to prioritize high-value targets. Cloudflare deployed Free and Paid WAF rules to block exploit traffic, published detections and rule IDs, and reported attribution and targeting patterns consistent with Asia-linked actors probing government, research, critical infrastructure, password managers, and edge VPN appliances.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
