Attackers in 2025 rapidly exploited both new and longstanding vulnerabilities, with mass scanning and weaponization occurring within hours of disclosure. The most targeted weaknesses included deserialization flaws, memory corruption in edge devices, and privilege escalation bugs, with some vulnerabilities—such as those in React Server Components and Microsoft WSUS—being compared to Log4Shell in terms of scale and impact. The Top 25 exploited vulnerabilities of the year highlighted systemic failures in patch management and asset visibility, as attackers leveraged both recent and decade-old flaws to gain initial access, deploy webshells, and compromise CI/CD pipelines.
Among the most critical issues was CVE-2025-11953, a remote code execution vulnerability in the React Native Community CLI’s Metro development server. This flaw, caused by unsanitized user input in the @react-native-community/cli-server-api package, allowed unauthenticated attackers to execute arbitrary OS commands via exposed HTTP endpoints. The vulnerability posed significant supply chain risks to mobile app development environments, enabling attackers to compromise developer workstations, steal credentials, and potentially pivot into corporate networks. Multiple national CERTs and security vendors issued urgent alerts and mitigation guidance due to the high exploitability and widespread exposure of this vulnerability.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
A year-end assessment reported that attackers in 2025 rapidly weaponized both new and longstanding vulnerabilities across enterprise software, edge devices, and critical infrastructure. The report highlighted widespread abuse of flaws in products such as React Server Components, Microsoft WSUS, Adobe Commerce, Citrix NetScaler, and Shellshock, often leading to webshells, credential theft, lateral movement, and ransomware.
Multiple CERTs and web application firewall vendors issued alerts and emergency protections in response to the high-risk React Native Metro server vulnerability. Recommended mitigation included upgrading to version 20.0.0 or later, restricting binding to localhost, and deploying network protections.
CVE-2025-11953 was identified as a critical unauthenticated remote code execution flaw in the @react-native-community/cli-server-api package affecting versions 4.8.0 through 20.0.0-alpha.2. The issue stems from OS command injection via unsanitized input handled by the open() function in the Metro development server.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.