Threat actors are actively exploiting React2Shell, a critical remote code execution flaw in React Server Components tracked as CVE-2025-55182, with related exposure also noted in Next.js as CVE-2025-66478. The bug stems from insecure deserialization in the React Server Components Flight protocol and allows unauthenticated attackers to upload malicious payloads and execute arbitrary code on vulnerable internet-facing servers. Public disclosure was quickly followed by advisories, proof-of-concept code, and reports of broad exploitation, while Microsoft and other researchers said hundreds of machines had already been hacked.
Follow-on campaigns have been widespread and largely opportunistic, ranging from credential-harvesting operations to malware deployment against organizations in multiple sectors and regions. Cisco Talos-linked reporting said at least 766 servers were compromised by an automated campaign that stole SSH keys, cloud tokens, API keys, Kubernetes and GitHub credentials, Docker metadata, and other environment secrets, including keys tied to AI platforms and payment services. Other investigations tied exploitation to XMRig, RustoBot, Kaiji, Sliver, CrossC2, Tactical RMM, VShell, and EtherRAT, along with persistence, reconnaissance, DNS-based exfiltration, and SSH key installation, underscoring how rapidly the vulnerability was weaponized after disclosure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Cisco Talos reported a widespread automated campaign exploiting internet-facing vulnerable React Server Components instances, attributing activity to UAT-10608. The payload harvested credentials, SSH keys, cloud tokens, API keys, and other secrets, with at least 766 servers compromised across multiple regions.
Reporting in early February 2026 indicated a notable change in how threat actors were exploiting React2Shell. This suggests the campaign evolved beyond its initial exploitation patterns.
By mid-December, Microsoft counted hundreds of compromised machines tied to React2Shell exploitation, indicating the campaign had scaled significantly. This represented a major escalation in observed impact.
BI.ZONE reported that adversaries exploited React2Shell during December 2025, including attacks on Russian companies in the insurance, e-commerce, and IT sectors. Observed post-exploitation included XMRig, RustoBot, Kaiji, Sliver, CrossC2, Tactical RMM, VShell, EtherRAT, persistence, and DNS-based exfiltration.
Threat researchers reported that CVE-2025-55182 was being actively exploited in the wild. This established that the vulnerability had moved from disclosure into real-world attacks.
JPCERT/CC published an advisory covering CVE-2025-55182 in React Server Components. The advisory reflects formal defender awareness and guidance around the vulnerability.
A GitHub repository published a proof-of-concept script for CVE-2025-55182, demonstrating exploitation of the React SSR/RSC remote code execution flaw. Public exploit code likely lowered the barrier for attackers to weaponize the bug.
A detailed write-up described React2Shell as a critical RCE affecting React Server Components and Next.js, including CVE-2025-55182 and CVE-2025-66478. The publication expanded public technical understanding of the flaw and affected ecosystem.
A public CVE entry for CVE-2025-55182 appeared, identifying the React Server Components server-side remote code execution issue later dubbed React2Shell. This marks the earliest public disclosure point visible in the references.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
cybersecuritydive.com
Open sourcecybersecuritydive.com
Open sourcebi-zone.medium.com
Open sourcejpcert.or.jp
Open sourcetheregister.com
Open sourcectrlaltintel.com
Open sourcegithub.com
Open sourceesentire.com
Open sourcehackerone.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.