← Front PageVulnerabilities Desk
Vulnerabilities
Multiple Threat Actors Exploit React2Shell (CVE-2025-55182)
Multiple threat actors actively exploit critical React2Shell RCE vulnerability (CVE-2025-55182) in React components.
Summary written by editorial AI · Source link below
CVSS10.0criticalCVE-2025-55182
Written by: Aragorn Tseng, Robert Weiner, Casey Charrier, Zander Work, Genevieve Stark, Austin Larsen Introduction On Dec. 3, 2025, a critical unauthenticated remote code execution (RCE) vulnerability in React Server Components, tracked as CVE-2025-55182 (aka "React2Shell"), was publicly disclosed. Shortly after disclosure, Google Threat Intelligence Group (GTIG) had begun observing widespread exploitation across many threat clusters, ranging from opportunistic cyber crime actors to suspected es
Continue at the source
Read the full report at Mandiant BlogExternal link — opens at Mandiant Blog in a new tab.
§
Continue with
More from the Vulnerabilities Desk
- Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores2d
- Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code2d
- Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities3d
- Government Rails Site Hit Hours After CVE Patch3d
- Critical Citrix NetScaler auth bypass now leveraged in attacks3d