A critical remote code execution (RCE) vulnerability, tracked as CVE-2025-55182 and affecting React Server Components in React versions 19.x and Next.js versions 15.x and 16.x with App Router, has been rapidly exploited by multiple China-nexus cyber threat groups, including Earth Lamia and Jackpot Panda. The vulnerability, also referred to as React2Shell, allows unauthenticated attackers to execute arbitrary code on affected servers. AWS has confirmed that its managed services are not impacted, but customers running vulnerable versions in their own environments are strongly urged to update to the latest patched releases. AWS has also updated its WAF managed rules to help mitigate exploitation attempts and provided guidance for deploying custom WAF rules as an interim defense.
Amazon's threat intelligence teams observed exploitation attempts within hours of the public disclosure, highlighting the speed at which state-sponsored actors operationalize new vulnerabilities. The vulnerability was initially disclosed by security researcher Lachlan Davidson and carries a maximum CVSS score of 10.0, underscoring its severity. While AWS has implemented multiple layers of automated protection, patching remains the most effective mitigation. Customers are advised to update React to versions 19.0.1, 19.1.2, or 19.2.1, and Next.js to patched versions, and to consider additional WAF protections as outlined in AWS advisories.

See which actors are running it and whether you're in range.
22 events from the most recent confirmed update back to the earliest known activity.
AWS later published a separate product advisory for CVE-2025-66478, another React Server Components remote code execution issue. This reflected continued security fallout and tracking around the React server-side vulnerability family.
As of January 7, 2026, GreyNoise had observed more than 8.1 million React2Shell attack sessions from 8,163 source IPs across 101 countries. The firm said daily attack volume remained in the hundreds of thousands, showing sustained global exploitation well after disclosure.
Microsoft said React2Shell exploitation had led to several hundred hacked machines across diverse organizations. The company noted attackers were using the flaw for malware deployment, ransomware, and chained post-exploitation activity.
A Metasploit update added support for exploiting React2Shell in Waku applications in addition to Next.js. The change broadened offensive tooling coverage for affected frameworks.
Researchers documented Weaxor ransomware being deployed through React2Shell, with attackers launching Cobalt Strike, disabling defenses, and encrypting a host shortly after exploitation. This marked a shift from opportunistic scanning and miners to ransomware operations.
Cloudflare reported seeing more than 1 billion React2Shell exploitation attempts in the 11 days after disclosure. The volume underscored the industrialized scale of scanning and attack automation around the flaw.
Google Threat Intelligence linked additional Chinese state-backed clusters, including UNC6600, UNC6586, UNC6588, UNC6603, and UNC6595, to React2Shell exploitation. Reporting also noted Iranian and financially motivated actors joining the attacks.
In the wake of the React2Shell crisis, React released further patches for additional vulnerabilities including CVE-2025-55183, CVE-2025-55184, and CVE-2025-67779. These follow-on issues were considered less severe but expanded the remediation scope for defenders.
JPCERT/CC said it had received incident reports involving exploitation of React2Shell against organizations in Japan. The notice confirmed the campaign had spread beyond initial reporting regions.
CISA added CVE-2025-55182 to its Known Exploited Vulnerabilities catalog and accelerated the federal patch deadline to December 12, 2025. The move reflected the speed and scale of active exploitation.
By December 10, reporting indicated attacks had surpassed 50 confirmed victim organizations across sectors and regions. Researchers also tracked more than a dozen intrusion clusters using malware ranging from cryptominers to backdoors and access tools.
Security telemetry showed large-scale automated exploitation delivering Mirai-derived loaders, Rondo miners, and other commodity payloads against vulnerable Node.js and Next.js systems. The activity was described as indiscriminate and heavily automated.
By December 8, multiple firms including VulnCheck, Trend Micro, and others released technical analyses covering exploit variants, WAF bypasses, in-memory webshells, and detection artifacts. These reports showed the exploit ecosystem was rapidly diversifying beyond simple PoCs.
After confirmed active exploitation, CISA required U.S. federal civilian agencies to remediate React2Shell by December 26, 2025. Government and industry sources also urged immediate threat hunting for signs of compromise.
A detection template for React2Shell was added to the nuclei-templates repository to help defenders and scanners identify vulnerable systems. This reflected rapid community operationalization of detection content around the flaw.
By early reporting after disclosure, researchers said more than 77,000 internet-exposed IPs were vulnerable and over 30 organizations had already been compromised. Observed post-exploitation included credential theft, reconnaissance, and malware deployment such as Cobalt Strike, Snowlight, and Vshell.
Cloudflare experienced a brief outage affecting a significant share of HTTP traffic while urgently changing WAF parsing and protections for React2Shell. The company said the disruption was caused by its mitigation rollout, not by an attack.
Major providers including AWS, Cloudflare, and Fastly rolled out web application firewall and related mitigations to block exploitation attempts. AWS also published interim detection and hunting guidance for customers running vulnerable self-managed environments.
After early bogus or broken exploit code appeared, functional proof-of-concept exploits were published and validated by researchers. Public exploit availability accelerated opportunistic and targeted exploitation.
AWS observed active exploitation attempts within hours of disclosure, attributing activity to China state-nexus groups including Earth Lamia and Jackpot Panda, along with unattributed clusters. The attacks included automated scanning as well as hands-on debugging of exploit payloads.
Following disclosure, patched React versions and related mitigation guidance from the React team and Vercel were released for affected deployments. Organizations were urged to patch immediately rather than rely only on compensating controls.
CVE-2025-55182, a critical unsafe deserialization flaw in React Server Components enabling unauthenticated remote code execution, was publicly disclosed. The issue also affected downstream frameworks such as Next.js using App Router.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 108 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
50 references tracked. Mallory keeps watching after this page renders.
aws.amazon.com
Open sourcedarktrace.com
Open sourcerapid7.com
Open sourcego.theregister.com
Open sourcegithub.com
Open sourcebleepingcomputer.com
Open sourcego.theregister.com
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.