Threat actors are actively exploiting React2Shell, a critical remote code execution flaw in React Server Components tracked as CVE-2025-55182, with related exposure also noted in Next.js as CVE-2025-66478. The bug stems from insecure deserialization in the React Server Components Flight protocol and allows unauthenticated attackers to upload malicious payloads and execute arbitrary code on vulnerable internet-facing servers. Public disclosure was quickly followed by advisories, proof-of-concept code, and reports of broad exploitation, while Microsoft and other researchers said hundreds of machines had already been hacked.
Follow-on campaigns have been widespread and largely opportunistic, ranging from credential-harvesting operations to malware deployment against organizations in multiple sectors and regions. Cisco Talos-linked reporting said at least 766 servers were compromised by an automated campaign that stole SSH keys, cloud tokens, API keys, Kubernetes and GitHub credentials, Docker metadata, and other environment secrets, including keys tied to AI platforms and payment services. Other investigations tied exploitation to XMRig, RustoBot, Kaiji, Sliver, CrossC2, Tactical RMM, VShell, and EtherRAT, along with persistence, reconnaissance, DNS-based exfiltration, and SSH key installation, underscoring how rapidly the vulnerability was weaponized after disclosure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
Cisco Talos reported a widespread automated campaign exploiting internet-facing vulnerable React Server Components instances, attributing activity to UAT-10608. The payload harvested credentials, SSH keys, cloud tokens, API keys, and other secrets, with at least 766 servers compromised across multiple regions.
Reporting in early February 2026 indicated a notable change in how threat actors were exploiting React2Shell. This suggests the campaign evolved beyond its initial exploitation patterns.
By mid-December, Microsoft counted hundreds of compromised machines tied to React2Shell exploitation, indicating the campaign had scaled significantly. This represented a major escalation in observed impact.
BI.ZONE reported that adversaries exploited React2Shell during December 2025, including attacks on Russian companies in the insurance, e-commerce, and IT sectors. Observed post-exploitation included XMRig, RustoBot, Kaiji, Sliver, CrossC2, Tactical RMM, VShell, EtherRAT, persistence, and DNS-based exfiltration.
As of 2025-12-12, Google Threat Intelligence Group said multiple China-nexus threat clusters were exploiting CVE-2025-55182 globally, including UNC6600 delivering the MINOCAT tunneler and UNC6586 delivering the SNOWLIGHT downloader. The report also cited AWS observations that Earth Lamia and Jackpot Panda were exploiting the vulnerability, marking a significant attribution and campaign-detail expansion.
Threat researchers reported that CVE-2025-55182 was being actively exploited in the wild. This established that the vulnerability had moved from disclosure into real-world attacks.
JPCERT/CC reported multiple victim cases in which several threat actors rapidly exploited CVE-2025-55182, including one server compromised by multiple payloads between December 5 and 7, 2025 before being defaced with a warning message. The report also said more than 100 suspicious IP addresses sent likely exploit traffic during the same period, indicating broad indiscriminate exploitation.
CISA added CVE-2025-55182 to its Known Exploited Vulnerabilities catalog, reflecting evidence of active exploitation. The action marked formal U.S. government recognition that React2Shell was being exploited in the wild.
JPCERT/CC published an advisory covering CVE-2025-55182 in React Server Components. The advisory reflects formal defender awareness and guidance around the vulnerability.
A GitHub repository published a proof-of-concept script for CVE-2025-55182, demonstrating exploitation of the React SSR/RSC remote code execution flaw. Public exploit code likely lowered the barrier for attackers to weaponize the bug.
A detailed write-up described React2Shell as a critical RCE affecting React Server Components and Next.js, including CVE-2025-55182 and CVE-2025-66478. The publication expanded public technical understanding of the flaw and affected ecosystem.
A public CVE entry for CVE-2025-55182 appeared, identifying the React Server Components server-side remote code execution issue later dubbed React2Shell. This marks the earliest public disclosure point visible in the references.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
cybersecuritydive.com
Open sourceblogs.jpcert.or.jp
Open sourcecybersecuritydive.com
Open sourcebi-zone.medium.com
Open sourcectrlaltintel.com
Open sourcegithub.com
Open sourceesentire.com
Open sourcehackerone.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.