logo

Defending against the CVE-2025-55182 (React2Shell) vulnerability in React Server Components

ID: dade1460-46d0-5c7d-bea8-c1674b122ca8

STIX ID: report--dade1460-46d0-5c7d-bea8-c1674b122ca8

Feed Name: Microsoft Security

Threat Score
90/100

Date Published: 2025-12-15

Date Updated: 2026-04-28

Author: Microsoft Defender Security Research Team

...
...

Microsoft Defender details CVE-2025-55182 (React2Shell), a critical (CVSS 10.0) pre-authentication RCE in React Server Components and Next.js that can be triggered by a single HTTP request; active exploitation has been observed (from December 5, 2025) including deployment of coin miners, RATs, and credential/secret harvesting. The report provides observed TTPs, IoCs (IPs, domains, file hashes, URLs), detection and hunting queries for Defender/XDR/Sentinel, and mitigation guidance including patched package versions, prioritization of internet‑facing assets, and WAF/MDVM recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.