logo

React2Shell and related RSC vulnerabilities threat brief: early exploitation activity and threat actor techniques

ID: 4cfe7d8c-19a5-5581-8414-137eb383a9b6

STIX ID: report--4cfe7d8c-19a5-5581-8414-137eb383a9b6

Feed Name: Cloudflare Blog

Threat Score
90/100

Date Published: 2025-12-11

Date Updated: 2026-04-27

Author: Cloudforce One

...
...

On December 3, 2025 Cloudflare observed immediate, large-scale scanning and active exploitation attempts targeting a critical React Server Components RCE (CVE-2025-55182, "React2Shell") and two related RSC vulnerabilities (CVE-2025-55183, CVE-2025-55184); activity included use of Nuclei, custom React2Shell scanners, Burp Suite, and Internet-scale asset discovery to prioritize high-value targets. Cloudflare deployed Free and Paid WAF rules to block exploit traffic, published detections and rule IDs, and reported attribution and targeting patterns consistent with Asia-linked actors probing government, research, critical infrastructure, password managers, and edge VPN appliances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.